Worldwide Agenda Ransomware Wave Targets VMware ESXi Servers
ID: 29be9bac-f148-54e7-b48a-2e8ca274ecb4
STIX ID: report--29be9bac-f148-54e7-b48a-2e8ca274ecb4
Feed Name: Dark Reading
Threat Score
Agenda (aka Qilin/Water Galura) has deployed a new Rust-based ransomware variant that actively targets VMware vCenter and ESXi servers; attackers deliver it via Cobalt Strike or RMM, use an embedded PowerShell to propagate and change ESXi host root passwords, upload payloads via SSH, and execute commands filelessly while employing evasion techniques including vulnerable drivers (BYOVD).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
