Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationactively-exploited-vulnerabilityinternet-exposed-serviceend-of-life-software

ESXiArgs Ransomware Exploited Unpatched VMware ESXi Servers Worldwide

Updated 29d agoFirst seen May 25, 20265 sources

A large-scale ESXiArgs ransomware campaign hit internet-exposed VMware ESXi servers by exploiting a long-known vulnerability in the OpenSLP service, with incident responders and national authorities warning that many affected systems had not applied available patches. CERT-FR issued an alert on active exploitation affecting VMware ESXi, while broad reporting described widespread compromises across organizations globally as attackers encrypted virtual machine files and dropped ransom notes on hypervisors.

VMware said the attacks did not stem from a newly discovered zero-day, but from exploitation of older, already patched weaknesses and insecurely exposed services on unsupported or unpatched ESXi versions. The incident renewed scrutiny of VMware security after earlier warnings that threat actors, including state-backed operators, had abused VMware flaws such as CVE-2020-4006 for initial access, persistence, and privileged movement inside enterprise environments, underscoring the risk posed by internet-facing virtualization infrastructure that lags on patching and hardening.

Share:
ESXiArgs Ransomware Exploited Unpatched VMware ESXi Servers Worldwide
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jan 9, 20266mo ago

Report says three VMware ESXi zero-days were chained before disclosure

SC Media reported that a trio of VMware ESXi zero-day vulnerabilities had been chained in attacks long before they were publicly disclosed. The report introduced a later attribution and technical-development update to the broader ESXi exploitation story.

Feb 6, 20233y ago

VMware publishes response to ESXiArgs ransomware attacks

VMware Security Response Center issued an official response to the ESXiArgs attacks, providing guidance and context on the ransomware activity affecting ESXi servers. This marked VMware's public response following the widespread exploitation reports.

Feb 3, 20233y ago

Mass exploitation campaign targets unpatched VMware ESXi servers

CERT-FR and BleepingComputer reported a large-scale campaign exploiting a VMware ESXi vulnerability to compromise exposed, unpatched servers worldwide. The activity was associated with the ESXiArgs ransomware attacks.

Dec 7, 20206y ago

NSA warns Russian state hackers are exploiting CVE-2020-4006

The NSA disclosed that Russian state-sponsored attackers were actively exploiting CVE-2020-4006 to compromise VMware systems, install web shells, and pivot into Active Directory and ADFS environments. The advisory described the activity as affecting multiple victims.

Dec 3, 20206y ago

VMware patches CVE-2020-4006 after NSA notification

VMware released a fix for CVE-2020-4006, a command-injection flaw in VMware products, after being notified by the NSA. Ars Technica reports the patch was issued the Thursday before 2020-12-07.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.