Ransomware Attacks Exploit VMware ESXi Vulnerabilities in Alarming Pattern
ID: a16bb1cc-dd6f-54ad-964d-462645180b8a
STIX ID: report--a16bb1cc-dd6f-54ad-964d-462645180b8a
Feed Name: The Hacker News
Security researchers report a recurring pattern of ransomware attacks against VMware ESXi and virtualization environments where attackers gain initial access (phishing, malicious downloads, vulnerability exploitation), escalate to obtain ESXi/vCenter credentials, deploy ransomware, delete or encrypt backups, exfiltrate data to public or attacker-controlled hosts, and spread to non-virtualized hosts; recent activity includes malvertising and trojanized WinSCP/PuTTY installers delivering Sliver and Cobalt Strike, and multiple ransomware families (LockBit, BlackCat, MorLock, etc.) are active.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
