The Evolution of ESXiArgs Ransomware
ID: 99dc316e-2b8e-5cc3-98df-f7695705a64e
STIX ID: report--99dc316e-2b8e-5cc3-98df-f7695705a64e
Feed Name: Censys Blog
Date Published: 2023-02-16
Date Updated: 2026-04-27
Author: Brenda Mendoza; The Censys Research Team
The Censys Research Team analyzed the ESXiArgs ransomware campaign targeting VMware ESXi hosts, reporting a surge of infections (just over 500 newly observed hosts concentrated in France, Germany, the Netherlands, and the UK) and tracing ransom-note variants back to October 2022. The report provides a timeline of activity (notable waves in February 2023), analysis of early victim hosts, differences in ransom notes and encryption methods, links to archived host data, and a public dashboard to monitor compromises and remediation status.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
