AUTO-UPDATED

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

A China-nexus threat actor is actively exploiting a critical directory-traversal vulnerability in Broadcom VMware vCenter servers to execute arbitrary code and deploy persistent backdoors across global networks.

Key Points

  • The campaign exploits CVE-2026-59310, a critical vulnerability with a CVSS score of 9.8, which allows for remote code execution with root privileges.
  • Researchers at QUIRSO identified 361 compromised IP addresses across 47 countries, with the highest infection rates in Germany, the U.S., Turkey, Iran, and France.
  • Attackers utilize a "linuxFile" backdoor, reverse SSH tunnels, and malicious cron jobs to maintain persistence and escalate administrative access.
  • The intrusion includes the deployment of Babuk-derived ransomware on ESXi hosts, which researchers believe may serve as a smokescreen to destroy forensic logs.
  • Evidence of Chinese-language artifacts, specific working hours, and reused research suggests the operation is conducted by a China-based advanced persistent threat group.

Why it Matters

This campaign highlights the severe risks posed by unpatched infrastructure vulnerabilities, as attackers can gain full root control over enterprise management servers within days of a disclosure. The use of sophisticated cleanup tools and ransomware as a distraction demonstrates an evolving strategy to evade detection and complicate incident response efforts for global organizations.
Internet Published by info@thehackernews.com (The Hacker News)
Read original