Ransomware attacks targeting VMware ESXi servers: everything you need to know
ID: 323b8ff3-7a06-5e1d-b826-42b52acb8eb3
STIX ID: report--323b8ff3-7a06-5e1d-b826-42b52acb8eb3
Feed Name: Wiz Blog
Threat Score
On February 3, 2023 researchers observed widespread exploitation of VMware ESXi OpenSLP CVE-2021-21974 to deploy ESXiArgs ransomware that encrypts virtual machine files on ESXi 6.5/6.7/7.0; the report provides IoCs (attacker IPs and networks), MITRE technique mappings, affected versions, mitigation commands to disable OpenSLP, and patch guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
