logo

BlackByte Targets ESXi Bug With Ransomware to Access Virtual Assets

ID: 6fb86ae8-d89d-58c5-a47c-9e2d44afc8d9

STIX ID: report--6fb86ae8-d89d-58c5-a47c-9e2d44afc8d9

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-08-28

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Security researchers observed BlackByte ransomware actors exploiting CVE-2024-37085—an ESXi authentication bypass tied to Active Directory user management—to gain privileged access, deploy a new encryptor (BlackByteNT), and mass-encrypt virtual machines; the report highlights AD-group manipulation, BYOVD techniques, self-propagation, impacted sectors, and recommended mitigations including disconnecting ESXi from AD and patching to ESXi 8.0 U3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.