Top Highlights
- A suspected China-linked APT exploited a critical vulnerability in VMware vCenter (CVE-2026-59310) shortly after its patch release, compromising 361 IPs across 47 countries.
- The attack involved sophisticated use of cron jobs, backdoors, account creation, and vSphere API abuse to establish persistent control over affected systems.
- The campaign aimed to deploy Babuk-like ransomware on ESXi hosts, but researchers believe the primary goal was distraction and obfuscation, using encryption and log destruction.
- The threat actor also deployed a GitHub-based Linux cleaner tool to erase evidence, suggesting efforts to avoid detection and analysis of their intrusion.
China-Linked Group Exploits VMware Vulnerability and Deploys Ransomware
Recently, cybersecurity experts identified a concerning attack targeting VMware vCenter servers. The attackers exploited a serious security flaw known as CVE-2026-59310, which allows remote code execution. This vulnerability was patched by the manufacturer a few days before the attack began. However, the threat actors launched their campaign shortly after the fix was made public. German researchers believe the attack was carried out by a Chinese-speaking group operating in Beijing or nearby. Their analysis points to Chinese-language scripts and tools, as well as activity patterns aligned with Chinese working hours. This suggests a deliberate effort by a China-nexus advanced persistent threat (APT) group to explore and compromise vulnerable systems worldwide.
The campaign has already impacted hundreds of systems across 47 countries, with a high concentration in Germany, the US, Turkey, Iran, and France. These targeted systems include both traditional VMware environments and cloud-based infrastructures, highlighting the broad scope of the threat. The attackers used a combination of known vulnerabilities, including an authentication bypass, to access and manipulate the targeted servers. They created new administrative accounts and launched scans that mimic legitimate VMware operations. This level of sophistication indicates a carefully planned effort to gain persistent access and evade detection.
Deployment of Babuk-Derived Ransomware and Evasive Tactics
Once inside the systems, the threat actors deployed ransomware with the “.babyk” extension, a hallmark of Babuk-derived malware. While analysts are still determining the full scope of the attack, initial findings suggest that ransomware was just one part of a broader intrusion strategy. The attack’s primary goal appears to be maintaining long-term access rather than immediate financial gain. The attackers employed various tactics to cover their tracks, such as encrypting log files and deleting evidence from temporary directories. They also used sophisticated tools like reverse SSH connections and custom scripts to establish remote control channels.
Moreover, the hackers set up multiple covert operations, including creating fake VMware services and local accounts on ESXi hosts. They manipulated system configurations to grant themselves privileged access and set persistent backdoors. Interestingly, they also tried to conceal their activity by installing cleanup tools on GitHub, possibly aiming to erase traces and avoid detection over time. This indicates a deliberate effort to evade cybersecurity defenses and complicate forensic investigations. Overall, the campaign demonstrates how skilled threat actors can blend multiple tactics to hide their true intentions, whether for espionage, disruption, or data theft, ultimately contributing to a landscape where defenders need to be increasingly vigilant and adaptive.
Stay Ahead with the Latest Tech Trends
Learn how the Internet of Things (IoT) is transforming everyday life.
Stay inspired by the vast knowledge available on Wikipedia.
CyberAttacks-V1
