A China-nexus threat actor is actively exploiting a critical directory-traversal vulnerability in Broadcom VMware vCenter servers to execute arbitrary code and deploy persistent backdoors across global networks.
Key Points
- The campaign exploits CVE-2026-59310, a critical vulnerability with a CVSS score of 9.8, which allows for remote code execution with root privileges.
- Researchers at QUIRSO identified 361 compromised IP addresses across 47 countries, with the highest infection rates in Germany, the U.S., Turkey, Iran, and France.
- Attackers utilize a "linuxFile" backdoor, reverse SSH tunnels, and malicious cron jobs to maintain persistence and escalate administrative access.
- The intrusion includes the deployment of Babuk-derived ransomware on ESXi hosts, which researchers believe may serve as a smokescreen to destroy forensic logs.
- Evidence of Chinese-language artifacts, specific working hours, and reused research suggests the operation is conducted by a China-based advanced persistent threat group.