logo

From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944

ID: 60ec1322-25fa-5a32-b961-832d101e37d7

STIX ID: report--60ec1322-25fa-5a32-b961-832d101e37d7

Feed Name: Threat Intelligence

Threat Score
85/100

Date Published: 2025-07-23

Date Updated: 2026-04-27

Author: Mandiant

...
...

**Executive summary:** This advisory details hypervisor-level ransomware activity attributed to UNC3944 that targets vCenter and ESXi to manipulate virtual disks and rapidly deploy ransomware with minimal forensic traces; it emphasizes three defensive pillars—proactive hardening (lockdown mode, execInstalledOnly, VM encryption, posture management), identity and architectural integrity (phishing-resistant MFA, isolated identity clusters, avoiding authentication loops), and advanced detection/recovery (centralized logging, high-fidelity SIEM detections, immutable air-gapped backups)—and warns that these TTPs are being adopted broadly by other ransomware actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.