logo

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

ID: 022e6e92-9ccf-5f84-aa20-4fd6495c2d33

STIX ID: report--022e6e92-9ccf-5f84-aa20-4fd6495c2d33

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-08-17

Date Updated: 2026-08-19

Author: [email protected] (The Hacker News)

...
...

Cybersecurity firm QUIRSO attributes active exploitation of a critical VMware vCenter directory-traversal flaw (CVE-2026-59310, CVSS 9.8) — and concurrent activity exploiting CVE-2026-59309 — to a suspected China-nexus APT. The attackers achieved root code execution on vCenter appliances via cron-based payload delivery, deployed a WebSocket-based backdoor ('linuxFile'), used reverse SSH implants, created privileged accounts, harvested vCenter credentials, and prepared ESXi hosts for ransomware ('.babyk' Babuk-derived). The campaign impacted hundreds of unique IPs across dozens of countries, includes a public GitHub repository used to distribute/update tooling and evidence-cleaning utilities, and exposes numerous IoCs (IPs, domains, filenames) and TTPs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.