Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
ID: 022e6e92-9ccf-5f84-aa20-4fd6495c2d33
STIX ID: report--022e6e92-9ccf-5f84-aa20-4fd6495c2d33
Feed Name: The Hacker News
Cybersecurity firm QUIRSO attributes active exploitation of a critical VMware vCenter directory-traversal flaw (CVE-2026-59310, CVSS 9.8) — and concurrent activity exploiting CVE-2026-59309 — to a suspected China-nexus APT. The attackers achieved root code execution on vCenter appliances via cron-based payload delivery, deployed a WebSocket-based backdoor ('linuxFile'), used reverse SSH implants, created privileged accounts, harvested vCenter credentials, and prepared ESXi hosts for ransomware ('.babyk' Babuk-derived). The campaign impacted hundreds of unique IPs across dozens of countries, includes a public GitHub repository used to distribute/update tooling and evidence-cleaning utilities, and exposes numerous IoCs (IPs, domains, filenames) and TTPs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
