logo

ESXWhy: A Look at ESXiArgs Ransomware

ID: 2221612c-e6cb-51a6-a457-e6ec395f29f2

STIX ID: report--2221612c-e6cb-51a6-a457-e6ec395f29f2

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2023-02-09

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

**Executive summary:** The Censys ARC report documents the ESXiArgs ransomware campaign (early February 2023) that leverages a VMware ESXi/OpenSLP vulnerability (CVE-2021-21974) to encrypt virtual machines on internet-facing ESXi hosts; the campaign has infected thousands of hosts (peak ~3,500–3,800), is concentrated in France and OVH infrastructure, has evolved to a variant that encrypts more data and removes BTC addresses to hinder tracking, and has at least some observed payments (~$88k) while defenders publish decryptors and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.