logo

Active ESXiArgs Ransomware Campaign

ID: ac26795b-b9b5-59a8-9e97-2b84854bd414

STIX ID: report--ac26795b-b9b5-59a8-9e97-2b84854bd414

Feed Name: Arctic Wolf Blog

Threat Score
78/100

Date Published: 2023-02-06

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs analyzed an active, global ransomware campaign (ESXiArgs) targeting internet-exposed VMware ESXi servers by likely exploiting CVE-2021-21974 in the OpenSLP service. The attackers deploy a script and an encryptor that targets VM-related files (.vmdk, .vmx, .nvram, .vmem, etc.), use a Tox ID in identical ransom notes, and employ a Sosemanuk-based cipher (likely derived from Babuk code); Arctic Wolf provides technical details, detection artifacts, and mitigation guidance (patch ESXi, disable SLP if needed, avoid exposing ESXi, and consider CISA recovery tools).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.