Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments
As part of an ongoing cyber espionage campaign, a threat actor known as Fire Ant has targeted networking and virtualization infrastructure.
According to a new analysis released today by Sygnia, the activity, which was noticed this year, is mainly intended to compromise network appliances and VMware ESXi and vCenter setups within enterprises.
According to the cybersecurity firm, the threat actor used a variety of cunning and advanced tactics to create multilayered attack kill chains that allowed access to segmented and restricted network assets in environments that were thought to be isolated.
By working through eradication operations and responding in real time to confinement and eradication actions, the attacker showed a high level of operational mobility and perseverance, prese...

