VMware ESXi zero-days likely exploited a year before disclosure
ID: fba90367-4c42-5f64-8134-9eb3d9b03f3f
STIX ID: report--fba90367-4c42-5f64-8134-9eb3d9b03f3f
Feed Name: Bleeping Computer
Huntress analyzed December 2025 intrusions where attackers — likely Chinese-speaking and using a compromised SonicWall VPN and Domain Admin credentials — deployed a sophisticated VMware ESXi exploit toolkit that leverages (and appears to predate) three VMware zero-days to escape guest VMs, install a hypervisor-level VSOCK backdoor (VSOCKpuppet), and stage exfiltration; artifacts (PDB paths, language usage) suggest development in 2023–2024 and a modular toolset that could be reused against new vulnerabilities, and researchers recommend applying ESXi updates and using YARA/Sigma detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
