logo

Analysis of Files Used in ESXiArgs Ransomware Attack Against VMware ESXi Servers

ID: 81746119-5272-5cce-8a9f-f4b67e28ee96

STIX ID: report--81746119-5272-5cce-8a9f-f4b67e28ee96

Feed Name: CloudSEK Blog

Threat Score
85/100

Date Published: 2023-02-09

Date Updated: 2026-04-27

...
...

Threat actors exploited CVE-2021-21974 in VMware ESXi to deploy the ESXiArgs ransomware: a Bash script (encrypt.sh) that prepares targets, renames VM files, kills VM processes, hides traces and drops a compiled ELF payload (encrypt) which uses an RSA public key and the Sosemanuk stream cipher to encrypt VM-related files; the report provides technical analysis, IoCs (hashes, BTC addresses), YARA rules, OSINT on widespread infections, and recommends patching and backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.