Suspected China-Affiliated Group Exploits VMware vCenter Vulnerability to Deploy Ransomware

Date:

Cybersecurity researchers have identified a severe exploitation campaign targeting a recently patched vulnerability in Broadcom’s VMware vCenter server, attributed to a suspected advanced persistent threat (APT) group linked to China. This campaign takes advantage of CVE-2026-59310, a high-severity directory-traversal vulnerability rated 9.8 on the CVSS scale. Exploits initiated shortly after the flaw’s public disclosure on July 29, 2026, have resulted in significant system compromises across various countries.

Overview of the Attack

The exploitation of CVE-2026-59310 began within days of the vulnerability’s announcement and was investigated by the German incident response firm QUIRSO. The researchers assessed with moderate confidence that the threat actor is a Chinese-speaking group operating in UTC+08:00, a time zone commonly used in Chinese-speaking regions. This assessment was based on multiple indicators, including the use of Chinese language in command scripts and tools, as well as operational patterns aligning with the identified time zone.

During this period, over 361 unique victim IP addresses across 47 countries were compromised, with notable incidents reported in Germany (55), the United States (41), Turkey (38), Iran (26), and France (25).

The Vulnerability in Focus

CVE-2026-59310 allows unauthorized access via a directory traversal attack, facilitating arbitrary code execution on vulnerable VMware vCenter systems. Analysis revealed that another related vulnerability, CVE-2026-59309, which presents an authentication bypass, was also being actively exploited. Reports indicate that before the attacks commenced, a malicious actor created an unauthorized administrative account on the vCenter server to facilitate further exploitation.

In particular, QUIRSO observed that even though the malicious account was created, it was not subsequently used, highlighting the sophisticated nature of the attack methodology.

Execution of the Attack

Initial activities by the attackers involved malicious cron jobs set up on compromised systems to execute backdoors and schedule further exploits. A particularly notable cron job logged a malformed file claiming to be related to syslog, which reflected the name of the vulnerability identifier. This was utilized to execute commands to retrieve backdoor payloads, enabling remote access to the compromised systems.

The backdoor, referred to as “linuxFile,” allows attackers to establish control over compromised servers through WebSocket connections, enabling them to send commands and execute them in real time. Communications are encrypted using the malware’s own cryptography methods, despite using unencrypted transport for data transfer.

Broader Implications of the Attack

While the immediate action of the threat group led to the deployment of ransomware on compromised ESXi hosts—files encrypted with the “.babyk” extension, presumably linked to Babuk ransomware—it remains ambiguous whether the ransomware was a final target or a diversionary tactic. The deployment of this ransomware may have compromised critical telemetry data, further complicating a comprehensive forensic analysis of the incident.

QUIRSO has urged organizations that utilize VMware vCenter to promptly implement the available patches and remain vigilant against suspicious activities within their systems. The incident exemplifies a growing trend of APT groups exploiting known vulnerabilities shortly after disclosures to maximize their impact.

What’s Next

Organizations relying on VMware products must prioritize the application of security patches and adopt robust monitoring practices to detect unusual activities. Additionally, possessing incident response plans that can handle rapid exploitations like these can mitigate potential damage. Security teams should consider training on recognizing signs of APT activities and holding simulations to prepare for similar attacks in the future.

Given the sophistication of the tactics employed, it is essential for enterprises to engage in regular vulnerability assessments and tighten their cybersecurity postures, particularly against the backdrop of threats from well-resourced APT groups.

By following the best practices outlined by cybersecurity professionals, organizations can protect themselves against the potential fallout from such targeted cyberattacks.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...