logo

The Evolution of ESXiArgs Ransomware

ID: 99dc316e-2b8e-5cc3-98df-f7695705a64e

STIX ID: report--99dc316e-2b8e-5cc3-98df-f7695705a64e

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2023-02-16

Date Updated: 2026-04-27

Author: Brenda Mendoza; The Censys Research Team

...
...

The Censys Research Team analyzed the ESXiArgs ransomware campaign targeting VMware ESXi hosts, reporting a surge of infections (just over 500 newly observed hosts concentrated in France, Germany, the Netherlands, and the UK) and tracing ransom-note variants back to October 2022. The report provides a timeline of activity (notable waves in February 2023), analysis of early victim hosts, differences in ransom notes and encryption methods, links to archived host data, and a public dashboard to monitor compromises and remediation status.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.