logo

Massive Ransomware Attack Targets VMware ESXi Servers

ID: 3c4fd5c0-5d0e-5740-a0fb-d87eaf76640c

STIX ID: report--3c4fd5c0-5d0e-5740-a0fb-d87eaf76640c

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2023-02-07

Date Updated: 2026-07-20

...
...

The report details a widespread ESXi Args ransomware campaign exploiting CVE-2021-21974 to target VMware ESXi servers (around 1,000 infected globally). It analyzes the encrypt.sh orchestrator and an ELF encryptor (SHA256: 11b1b237...), describes targeted VM file extensions and persistence/cleanup actions (renaming VM config entries, replacing index.html and /etc/motd with ransom notes, deleting logs), outlines the crypto (RSA + Sosemanuk) and usage parameters, provides IOCs and MITRE ATT&CK mappings, and recommends patching vulnerable ESXi versions, checking for malicious vmtools.py, restoring offline backups, and disabling unnecessary services such as port 427.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.