logo

Ransomware Attacks Exploit VMware ESXi Vulnerabilities in Alarming Pattern

ID: a16bb1cc-dd6f-54ad-964d-462645180b8a

STIX ID: report--a16bb1cc-dd6f-54ad-964d-462645180b8a

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-23

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Security researchers report a recurring pattern of ransomware attacks against VMware ESXi and virtualization environments where attackers gain initial access (phishing, malicious downloads, vulnerability exploitation), escalate to obtain ESXi/vCenter credentials, deploy ransomware, delete or encrypt backups, exfiltrate data to public or attacker-controlled hosts, and spread to non-virtualized hosts; recent activity includes malvertising and trojanized WinSCP/PuTTY installers delivering Sliver and Cobalt Strike, and multiple ransomware families (LockBit, BlackCat, MorLock, etc.) are active.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.