Tuesday, May 13, 2025
HomeCyber Security NewsHackers Actively Exploiting VMware ESXi Servers to Deploy Ransomware

Hackers Actively Exploiting VMware ESXi Servers to Deploy Ransomware

Published on

SIEM as a Service

Follow Us on Google News

CERT-FR, the French Computer Emergency Response Team (CERT-FR), as well as administrators and hosting providers, have issued a warning concerning new ransomware, called ESXiArgs, that has been discovered.

This vulnerability makes it possible for the attackers to deploy the ESXiArgs ransomware, which can have serious consequences for the affected servers and the data stored on them. 

It is important for administrators and hosting providers to ensure that their VMware ESXi servers are patched and up-to-date to prevent such attacks.

- Advertisement - Google News

Behaviors Identified

  • Security analysts have determined that the compromise vector is based on an OpenSLP vulnerability that might be CVE-2021-21974.
  • The malware deploys a public key in /tmp/public.pem in order to encrypt its data.
  • The encryption process specifically targets files in virtual machines.
  • In an attempt to unblock the files on virtual machines, the malware kills the VMX process to shut down the virtual machines.
  • Argsfiles are created by the malware in order to store arguments passed to the encrypted binary as parameters.
  • The data was not exfiltrated in any way.

New ESXiArgs ransomware

Recently, there has been a new ransomware attack that has caught the attention of security experts. Upon analysis of the ransom notes left behind by the attackers, it has been determined that this attack does not seem to be related to the Nevada Ransomware. 

Instead, the ransom notes appear to be from a completely different, or “new,” ransomware family. This discovery highlights the ever-evolving nature of cyber threats and the need for constant vigilance and updates to security measures. 

After conducting a thorough review, the analyst has determined that the data in question has not been infiltrated. The investigation was prompted by an attack on a machine with over 500 GB of data stored on it, which showed typical daily usage of only 2 Mbps. 

In order to validate this conclusion, the analyst also reviewed traffic statistics for the past 90 days. No evidence was found of any outbound data transfer.

There have also been reports that victims have found ransom notes on locked systems with the names “ransom.html” and “How to Restore Your Files.html”.

Systems affected by CVE-2021-21974

There are a number of systems affected by CVE-2021-21974, including:

  • ESXi versions 7.x prior to ESXi70U1c-17325551
  • ESXi versions 6.7.x prior to ESXi670-202102401-SG
  • ESXi versions 6.5.x prior to ESXi650-202102101-SG

ESXiArgs Technical Details

As a result of analyzing the script and the encryption encryptor, we have gained a deeper understanding of the attacks. There are several files that are stored in the /tmp folder when the server is hacked:-

  • encrypt – The encryptor ELF executable.
  • encrypt[.]sh – Shell scripts that perform various tasks prior to the execution of an encryptor, serving as the attack logic.
  • public[.]pem – The key used to encrypt a file is a public RSA key.
  • motd – The ransom note in text form will be copied to /etc/motd, so it is shown on login. The server’s original file will be copied to /etc/motd1.
  • index[.]html -ESXi’s home page will be replaced with the ransom note in HTML format. In the same folder, index1.html will be copied from the server’s original file.

This security breach has affected dozens of Italy organizations and caused concern among many others. The incident involved a threat to lock these organizations out of their systems, and it is likely that many of them have already been affected. 

In response to this situation, many more organizations have been warned to take action in order to avoid falling victim to this attack. The widespread nature of this incident has highlighted the importance of maintaining strong security measures to protect against similar threats in the future.

Network Security Checklist – Download Free E-Book

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Researchers Uncover Remote IT Job Fraud Scheme Involving North Korean Nationals

The United States indicted fourteen North Korean nationals for orchestrating a sophisticated scheme to...

Attackers Leverage Unpatched Output Messenger 0‑Day to Deliver Malicious Payloads

A Türkiye-affiliated espionage threat actor, tracked by Microsoft Threat Intelligence as Marbled Dust (also...

Cobalt Strike 4.11.1 Released With SSL Checkbox Fix

Cobalt Strike has announced the release of version 4.11.1, an out-of-band update addressing several...

Apple Releases Security Patches to Fix Critical Data Exposure Flaws

Apple released critical security updates for macOS Sequoia 15.5 on May 12, 2025, addressing...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Researchers Uncover Remote IT Job Fraud Scheme Involving North Korean Nationals

The United States indicted fourteen North Korean nationals for orchestrating a sophisticated scheme to...

Attackers Leverage Unpatched Output Messenger 0‑Day to Deliver Malicious Payloads

A Türkiye-affiliated espionage threat actor, tracked by Microsoft Threat Intelligence as Marbled Dust (also...

Cobalt Strike 4.11.1 Released With SSL Checkbox Fix

Cobalt Strike has announced the release of version 4.11.1, an out-of-band update addressing several...