Active ESXiArgs Ransomware Campaign
ID: ac26795b-b9b5-59a8-9e97-2b84854bd414
STIX ID: report--ac26795b-b9b5-59a8-9e97-2b84854bd414
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs analyzed an active, global ransomware campaign (ESXiArgs) targeting internet-exposed VMware ESXi servers by likely exploiting CVE-2021-21974 in the OpenSLP service. The attackers deploy a script and an encryptor that targets VM-related files (.vmdk, .vmx, .nvram, .vmem, etc.), use a Tox ID in identical ransom notes, and employ a Sosemanuk-based cipher (likely derived from Babuk code); Arctic Wolf provides technical details, detection artifacts, and mitigation guidance (patch ESXi, disable SLP if needed, avoid exposing ESXi, and consider CISA recovery tools).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
