Tag: VMware ESXi

Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims
News

Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims

The infamous cybercrime gang Scattered Spider has been linked by cybersecurity researchers to a new wave of cyberattacks that target financial systems, raising questions about their claims of staying "dark." According to threat intelligence company ReliaQuest, there are signs that the threat actor has turned their attention to the financial industry. This is corroborated by a recent targeted attack into an unidentified U.S. banking institution and a rise in lookalike domains that may be associated with the group and aimed against the industry vertical. According to the organization, Scattered Spider first obtained access by using Azure Active Directory Self-Service Password Management to reset an executive's password and social engineer their account. They then gained access to p...
AWS EKS Security Best PracticesScattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
News

AWS EKS Security Best PracticesScattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure

VMware ESXi hypervisors are the subject of attacks by the well-known cybercrime gang Scattered Spider that target the North American retail, airline, and transportation industries. The fundamental strategies employed by the gang have not changed and do not depend on software exploits. According to a thorough examination by Google's Mandiant team, they instead employ a tried-and-true strategy that revolves upon phone calls to an IT help desk. The actors are aggressive, resourceful, and especially adept at circumventing even well-established security measures through social engineering. They target an organization's most important systems and data using targeted, campaign-driven attacks rather than opportunistic ones. The threat actors, also known as 0ktapus, Muddled Libra, Octo Te...
Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments
News

Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments

As part of an ongoing cyber espionage campaign, a threat actor known as Fire Ant has targeted networking and virtualization infrastructure. According to a new analysis released today by Sygnia, the activity, which was noticed this year, is mainly intended to compromise network appliances and VMware ESXi and vCenter setups within enterprises. According to the cybersecurity firm, the threat actor used a variety of cunning and advanced tactics to create multilayered attack kill chains that allowed access to segmented and restricted network assets in environments that were thought to be isolated. By working through eradication operations and responding in real time to confinement and eradication actions, the attacker showed a high level of operational mobility and perseverance, prese...
Broadcom fixes three VMware zero-days exploited in attacks
News

Broadcom fixes three VMware zero-days exploited in attacks

Customers were alerted by Broadcom today to three VMware zero-day vulnerabilities that the Microsoft Threat Intelligence Center had identified as being exploited in attacks. VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform are among the VMware ESX products that are affected by the vulnerabilities (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226). These vulnerabilities can be used by attackers with root or privileged administrator access to get out of the virtual machine's sandbox. An attacker could take control of the hypervisor itself in this scenario if they had already infiltrated the guest operating system of a virtual machine read more about Broadcom fixes three VMware zero-days exploited in attacks. Get up to date on the latest cyb...
BlackByte Ransomware Exploits VMware ESXi Flaw in Latest Attack Wave
News

BlackByte Ransomware Exploits VMware ESXi Flaw in Latest Attack Wave

The threat actors responsible for the BlackByte ransomware gang have been seen disabling security measures by utilizing a number of vulnerable drivers in addition to a newly patched security flaw that affects VMware ESXi hypervisors. According to a technical report shared with The Hacker News by Cisco Talos, the BlackByte ransomware group is still using the same tactics, techniques, and procedures (TTPs) that have been the cornerstone of its tradecraft since its founding. This includes repeatedly using vulnerable drivers to get around security measures and deploying a wormable, self-propagating ransomware encryptor. The e-crime gang is veering away from tried-and-true methods, as evidenced by their exploitation of CVE-2024-37085, an authentication bypass vulnerability in VMware ESXi...
VMware ESXi Flaw Exploited by Ransomware Groups for Admin Access
News

VMware ESXi Flaw Exploited by Ransomware Groups for Admin Access

"Several" ransomware gangs have been actively using a recently patched security vulnerability affecting VMware ESXi hypervisors to obtain elevated permissions and install malware that encrypts files. The attacks leverage CVE-2024-37085 (CVSS score: 6.8), a vulnerability that circumvents Active Directory integration authentication and grants an attacker administrative access to the server. The Broadcom-owned VMware noted in an advisory published in late June 2024 that a malicious actor with sufficient permissions in Active Directory (AD) can obtain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group read more about VMware ESXi Flaw Exploited by Ransomware Groups for Admin Access. Get up to date on the late...
Scattered Spider Adopts RansomHub and Qilin Ransomware for Cyber Attacks
News

Scattered Spider Adopts RansomHub and Qilin Ransomware for Cyber Attacks

Microsoft has disclosed that the notorious cybercrime collective known as Scattered Spider has included ransomware strains like Qilin and RansomHub in its repertoire. A threat actor noted for using complex social engineering techniques to compromise targets and create persistence for later exploitation and data theft is called the "Scattered Spider." Additionally, it has a history of using the BlackCat ransomware to attack VMware ESXi servers. It overlaps with activity clusters that are monitored under the names 0ktapus, Octo Tempest, and UNC3944 by the larger cybersecurity community. An important gang member was reportedly detained in Spain last month read more about Scattered Spider Adopts RansomHub and Qilin Ransomware for Cyber Attacks. Get up to date on the latest cybersecur...
Linux version of TargetCompany ransomware focuses on VMware ESXi
News

Linux version of TargetCompany ransomware focuses on VMware ESXi

Researchers have discovered a new Linux ransomware strain of the TargetCompany family that targets VMware ESXi installations and delivers and runs payloads via a customized shell script. The TargetCompany ransomware operation, also known as Mallox, FARGO, and Tohnichi, first surfaced in June 2021 and has been concentrating on database attacks (MySQL, Oracle, and SQL Server) against businesses mostly located in Taiwan, South Korea, Thailand, and India. The antivirus company Avast declared in February 2022 that a free decryption tool covering versions released up to that time was available. However, the gang resumed its usual activities by September, focusing on Microsoft SQL servers that were at risk of vulnerability and threatening victims with the release of stolen data over Telegr...
Ransomware Attacks Exploit VMware ESXi Vulnerabilities in Alarming Pattern
News

Ransomware Attacks Exploit VMware ESXi Vulnerabilities in Alarming Pattern

Regardless of the file-encrypting malware used, ransomware assaults against VMware ESXi infrastructure follow a well-established pattern, according to recent research. Cybersecurity firm Sygnia stated in a report shared with The Hacker News that virtualization platforms are an essential part of organizational IT infrastructure, but they frequently have built-in misconfigurations and vulnerabilities, making them a lucrative and highly effective target for threat actors to abuse. The Israeli business discovered that attacks on virtualization environments follow a similar pattern of events through its incident response work with different ransomware families, including LockBit, HelloKitty, BlackMatter, RedAlert (N13V), Scattered Spider, Akira, Cactus, BlackCat, and Cheerscrypt read mor...