Tag: ransomware

Chinese Hackers Exploit VMware ESXi Zero-Day to Backdoor Virtual Machines

Security Advisory

Introduction Recently, a Chinese-sponsored hacking group, tracked as UNC3886 by cybersecurity firm Mandiant, has made headlines for exploiting a zero-day vulnerability in VMware ESXi to infiltrate Windows and Linux virtual machines (VMs) and steal sensitive data. In this blog post, we will delve into the details of the attack, the techniques employed by the hackers,…

Read more

ESXiArgs Ransomware -Recover tool is now available!

Security Advisory

CISA has developed ESXiArgs-Recover, a tool aimed at assisting organizations in their attempts to recover virtual machines affected by ESXiArgs ransomware attacks. Some organizations have reported successful recovery of files without having to pay a ransom. The tool has been created using publicly available resources, including a tutorial by Enes Sonmez and Ahmet Aykac. It…

Read more

ESXiArgs Ransomware: Alguien está encriptando servidores VMware ESXi 6.X sin parches que están abiertos a Internet.

Uncategorized

Administradores, proveedores de alojamiento y el equipo francés de respuesta a emergencias informáticas (CERT-FR) están emitiendo advertencias de que los atacantes están atacando activamente servidores VMware ESXi que son vulnerables debido a una debilidad de ejecución de código remoto sin parches de hace dos años. El objetivo final de estos atacantes es instalar ransomware en…

Read more

ESXiArgs Ransomware: Someone is encrypting an unpatched VMware ESXi 6.X servers that are open to the internet.

Security Advisory

Warnings are being issued by administrators, hosting providers, and the French Computer Emergency Response Team (CERT-FR) that attackers are actively targeting VMware ESXi servers that are vulnerable due to a two-year-old unpatched remote code execution flaw. The ultimate goal of these attackers is to install ransomware on these systems. The vulnerability tracked as CVE-2021-21974 is…

Read more

New ransomware is targeting Windows and Linux VMware ESXi servers – RedAlert/N13V

Security Advisory

The ransomware was discovered by MalwareHunterTeam, who tweeted images of the malicious actor’s data leak webpage. The ransomware was called RedAlert as it has this name in the ransom note left for the victims, however, the criminals call their operation N13V, as we can see from the screenshots provided by the BleepingComputer website. We know…

Read more