logo

Ransomware gang uses SSH tunnels for stealthy VMware ESXi access

ID: 8b39fb22-b4c6-5d70-8f2c-5b18b982f919

STIX ID: report--8b39fb22-b4c6-5d70-8f2c-5b18b982f919

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-01-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Ransomware operators are abusing ESXi's built-in SSH to create stealthy SSH tunnels (e.g., remote port-forwarding/SOCKS) for persistence and lateral movement on VMware ESXi appliances; compromises arise from exploited known flaws or stolen admin credentials, and detection is hampered by distributed ESXi logs and attacker log tampering—organizations are advised to centralize ESXi logs and integrate them into SIEMs to improve visibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.