The ESXiArgs ransomware attack that started infecting servers of VMware ESXi hypervisors from February 2, 2023, is the latest of a long list of malicious campaigns exploiting ESXi vulnerabilities.
Threat intelligence firm Recorded Future has tracked ESXi-focused ransomware since 2020. In a threat analysis report published on February 13, 2023, the company said it believes virtual machines (VM) orchestration tools such as ESXi will increasingly be used by malicious actors in the future “as organizations continue virtualizing their critical infrastructure and business systems.”
VMware’s hypervisors, however, are increasingly appealing to threat actors, with the report noting “an approximately three-fold increase in ransomware targeting ESXi between 2021 and 2022, with offerings available from many groups including ALPHV, LockBit, and BlackBasta.”
No tags.