logo

Worldwide Agenda Ransomware Wave Targets VMware ESXi Servers

ID: 29be9bac-f148-54e7-b48a-2e8ca274ecb4

STIX ID: report--29be9bac-f148-54e7-b48a-2e8ca274ecb4

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-03-26

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Agenda (aka Qilin/Water Galura) has deployed a new Rust-based ransomware variant that actively targets VMware vCenter and ESXi servers; attackers deliver it via Cobalt Strike or RMM, use an embedded PowerShell to propagate and change ESXi host root passwords, upload payloads via SSH, and execute commands filelessly while employing evasion techniques including vulnerable drivers (BYOVD).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.