Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Shaping the Future of NVD: Share Your Feedback on AI-Driven Vulnerability Management

September 17, 2026

Suspected China-Linked Group Exploits VMware Flaw to Launch Babuk Ransomware

September 16, 2026

AI accelerates attacks on outdated systems, experts warn

September 16, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » Suspected China-Linked Group Exploits VMware Flaw to Launch Babuk Ransomware
Cybercrime and Ransomware

Suspected China-Linked Group Exploits VMware Flaw to Launch Babuk Ransomware

Staff WriterBy Staff WriterSeptember 16, 2026No Comments3 Mins Read2 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Top Highlights

  1. A suspected China-linked APT exploited a critical vulnerability in VMware vCenter (CVE-2026-59310) shortly after its patch release, compromising 361 IPs across 47 countries.
  2. The attack involved sophisticated use of cron jobs, backdoors, account creation, and vSphere API abuse to establish persistent control over affected systems.
  3. The campaign aimed to deploy Babuk-like ransomware on ESXi hosts, but researchers believe the primary goal was distraction and obfuscation, using encryption and log destruction.
  4. The threat actor also deployed a GitHub-based Linux cleaner tool to erase evidence, suggesting efforts to avoid detection and analysis of their intrusion.

China-Linked Group Exploits VMware Vulnerability and Deploys Ransomware

Recently, cybersecurity experts identified a concerning attack targeting VMware vCenter servers. The attackers exploited a serious security flaw known as CVE-2026-59310, which allows remote code execution. This vulnerability was patched by the manufacturer a few days before the attack began. However, the threat actors launched their campaign shortly after the fix was made public. German researchers believe the attack was carried out by a Chinese-speaking group operating in Beijing or nearby. Their analysis points to Chinese-language scripts and tools, as well as activity patterns aligned with Chinese working hours. This suggests a deliberate effort by a China-nexus advanced persistent threat (APT) group to explore and compromise vulnerable systems worldwide.

The campaign has already impacted hundreds of systems across 47 countries, with a high concentration in Germany, the US, Turkey, Iran, and France. These targeted systems include both traditional VMware environments and cloud-based infrastructures, highlighting the broad scope of the threat. The attackers used a combination of known vulnerabilities, including an authentication bypass, to access and manipulate the targeted servers. They created new administrative accounts and launched scans that mimic legitimate VMware operations. This level of sophistication indicates a carefully planned effort to gain persistent access and evade detection.

Deployment of Babuk-Derived Ransomware and Evasive Tactics

Once inside the systems, the threat actors deployed ransomware with the “.babyk” extension, a hallmark of Babuk-derived malware. While analysts are still determining the full scope of the attack, initial findings suggest that ransomware was just one part of a broader intrusion strategy. The attack’s primary goal appears to be maintaining long-term access rather than immediate financial gain. The attackers employed various tactics to cover their tracks, such as encrypting log files and deleting evidence from temporary directories. They also used sophisticated tools like reverse SSH connections and custom scripts to establish remote control channels.

Moreover, the hackers set up multiple covert operations, including creating fake VMware services and local accounts on ESXi hosts. They manipulated system configurations to grant themselves privileged access and set persistent backdoors. Interestingly, they also tried to conceal their activity by installing cleanup tools on GitHub, possibly aiming to erase traces and avoid detection over time. This indicates a deliberate effort to evade cybersecurity defenses and complicate forensic investigations. Overall, the campaign demonstrates how skilled threat actors can blend multiple tactics to hide their true intentions, whether for espionage, disruption, or data theft, ultimately contributing to a landscape where defenders need to be increasingly vigilant and adaptive.

Stay Ahead with the Latest Tech Trends

Learn how the Internet of Things (IoT) is transforming everyday life.

Stay inspired by the vast knowledge available on Wikipedia.

CyberAttacks-V1

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAI accelerates attacks on outdated systems, experts warn
Next Article Shaping the Future of NVD: Share Your Feedback on AI-Driven Vulnerability Management
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

CISA Flags Critical Ray Flaw for Browser-Based RCE Exploits

September 13, 2026

TWINLOOT Exploits SharePoint and Teams to Steal Credentials and Lateral Movement

September 10, 2026

Windchill Web Shell Exposes Credentials and Maps Engineering Data

September 7, 2026

Comments are closed.

Latest Posts

Suspected China-Linked Group Exploits VMware Flaw to Launch Babuk Ransomware

September 16, 2026

CISA Flags Critical Ray Flaw for Browser-Based RCE Exploits

September 13, 2026

TWINLOOT Exploits SharePoint and Teams to Steal Credentials and Lateral Movement

September 10, 2026

Windchill Web Shell Exposes Credentials and Maps Engineering Data

September 7, 2026
Don't Miss

CISA Flags Critical Ray Flaw for Browser-Based RCE Exploits

By Staff WriterSeptember 13, 2026

Fast Facts 1. CISA added a critical vulnerability in Ray (CVE-2025-62593, CVSS 9.4) to its…

TWINLOOT Exploits SharePoint and Teams to Steal Credentials and Lateral Movement

September 10, 2026

Windchill Web Shell Exposes Credentials and Maps Engineering Data

September 7, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Shaping the Future of NVD: Share Your Feedback on AI-Driven Vulnerability Management
  • Suspected China-Linked Group Exploits VMware Flaw to Launch Babuk Ransomware
  • AI accelerates attacks on outdated systems, experts warn
  • Hospitality sector targeted with specialized cyber attack scans
  • Rising Above: Discovering Hope in Challenging Tech Times
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Shaping the Future of NVD: Share Your Feedback on AI-Driven Vulnerability Management

September 17, 2026

Suspected China-Linked Group Exploits VMware Flaw to Launch Babuk Ransomware

September 16, 2026

AI accelerates attacks on outdated systems, experts warn

September 16, 2026
Most Popular

CISA Alerts: Critical Vulnerability in Splunk Enterprise Under Active Attack

June 19, 2026189 Views

Salesforce Disables Klue App After Data Breach from Token Abuse

June 19, 2026186 Views

Gefährliche Angriffe: Wie Cyberkriminelle Ihre Identität angreifen

January 29, 2026186 Views

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.