logo

VMware ESXi zero-days likely exploited a year before disclosure

ID: fba90367-4c42-5f64-8134-9eb3d9b03f3f

STIX ID: report--fba90367-4c42-5f64-8134-9eb3d9b03f3f

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-01-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Huntress analyzed December 2025 intrusions where attackers — likely Chinese-speaking and using a compromised SonicWall VPN and Domain Admin credentials — deployed a sophisticated VMware ESXi exploit toolkit that leverages (and appears to predate) three VMware zero-days to escape guest VMs, install a hypervisor-level VSOCK backdoor (VSOCKpuppet), and stage exfiltration; artifacts (PDB paths, language usage) suggest development in 2023–2024 and a modular toolset that could be reused against new vulnerabilities, and researchers recommend applying ESXi updates and using YARA/Sigma detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.