Introduction Recently, a Chinese-sponsored hacking group, tracked as UNC3886 by cybersecurity firm Mandiant, has made headlines for exploiting a zero-day vulnerability in VMware ESXi to infiltrate Windows and Linux virtual machines (VMs) and steal sensitive data. In this blog post, we will delve into the details of the attack, the techniques employed by the hackers,…
Read moreTag: ransomware
ESXiArgs Ransomware -Recover tool is now available!
CISA has developed ESXiArgs-Recover, a tool aimed at assisting organizations in their attempts to recover virtual machines affected by ESXiArgs ransomware attacks. Some organizations have reported successful recovery of files without having to pay a ransom. The tool has been created using publicly available resources, including a tutorial by Enes Sonmez and Ahmet Aykac. It…
Read moreESXiArgs Ransomware: Alguien está encriptando servidores VMware ESXi 6.X sin parches que están abiertos a Internet.
Administradores, proveedores de alojamiento y el equipo francés de respuesta a emergencias informáticas (CERT-FR) están emitiendo advertencias de que los atacantes están atacando activamente servidores VMware ESXi que son vulnerables debido a una debilidad de ejecución de código remoto sin parches de hace dos años. El objetivo final de estos atacantes es instalar ransomware en…
Read moreESXiArgs Ransomware: Someone is encrypting an unpatched VMware ESXi 6.X servers that are open to the internet.
Warnings are being issued by administrators, hosting providers, and the French Computer Emergency Response Team (CERT-FR) that attackers are actively targeting VMware ESXi servers that are vulnerable due to a two-year-old unpatched remote code execution flaw. The ultimate goal of these attackers is to install ransomware on these systems. The vulnerability tracked as CVE-2021-21974 is…
Read moreNew ransomware is targeting Windows and Linux VMware ESXi servers – RedAlert/N13V
The ransomware was discovered by MalwareHunterTeam, who tweeted images of the malicious actor’s data leak webpage. The ransomware was called RedAlert as it has this name in the ransom note left for the victims, however, the criminals call their operation N13V, as we can see from the screenshots provided by the BleepingComputer website. We know…
Read more