logo

Ransomware Gangs Exploit ESXi Bug for Instant, Mass Encryption of VMs

ID: cea9efe5-a5ac-5671-b55d-2f8c7ea2e8bf

STIX ID: report--cea9efe5-a5ac-5671-b55d-2f8c7ea2e8bf

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-07-30

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Multiple ransomware groups have been exploiting VMware ESXi vulnerability CVE-2024-37085 — which grants full ESXi administrative access to any AD domain group named "ESX Admins" — to quickly escalate privileges and deploy ransomware (e.g., Black Basta, Akira) across virtualized environments; Broadcom has released a patch and organizations are urged to apply it and improve hypervisor hygiene and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.