Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese APT Exploits VMware Flaw for Ransomware Attack

Chinese APT Exploits VMware Flaw for Ransomware Attack

Posted on August 17, 2026 By CWS

In a significant cybersecurity incident, researchers have linked the exploitation of a patched vulnerability in VMware vCenter to a suspected Chinese advanced persistent threat (APT) group. The flaw, identified as CVE-2026-59310, carries a critical CVSS score of 9.8 and enables directory traversal attacks that can lead to arbitrary code execution. Broadcom addressed this issue with a patch released on July 29, 2026.

Details of the Exploitation

The cybersecurity firm QUIRSO has assessed, with moderate confidence, that the campaign leveraging CVE-2026-59310 is facilitated by threat actors fluent in Chinese. They are likely operating within the UTC+08:00 time zone, commonly used in China. This conclusion is drawn from various indicators, such as Chinese-language artifacts in scripts, the reuse of research from Chinese sources, and the absence of attacks targeting systems within mainland China.

This campaign began exploiting the flaw merely five days after its public disclosure, affecting 361 victim IP addresses in 47 countries. Nations such as Germany, the U.S., Turkey, Iran, and France were among the hardest hit, with significant numbers of compromised systems.

Technical Analysis of the Attack

QUIRSO’s analysis reveals that compromised vCenter servers were targeted using both CVE-2026-59310 and another flaw, CVE-2026-59309, which allows authentication bypass. Evidence shows malicious activities tied to CVE-2026-59309 as early as August 1, 2026. This included creating an administrative account from an IP address associated with suspicious activity.

The exploitation of CVE-2026-59310 involved manipulating the cron daemon to execute a backdoor downloaded from a remote server. The attackers used naming conventions that mimic VMware’s syslog file structure, suggesting a sophisticated attempt to embed malicious files within privileged execution paths.

Ransomware Deployment and Observations

The attack culminated in the deployment of ransomware on ESXi hosts, encrypting files with the .babyk extension, commonly associated with Babuk-derived ransomware. QUIRSO has not confirmed whether this was the primary goal of the operation or a diversion tactic to hinder forensic analysis by encrypting log files and concealing attacker activities.

Further investigation revealed the use of cron jobs to execute malicious payloads, including scripts that enabled persistent access and deployed reverse SSH binaries. These actions were part of a broader effort to maintain control over compromised systems while blending in with legitimate VMware operations.

Conclusion and Implications

This cyber attack underscores the persistent threat posed by sophisticated APT groups exploiting vulnerabilities in widely-used software platforms. The rapid exploitation of the VMware vCenter flaw highlights the need for timely patch management and comprehensive security measures to protect critical infrastructure. As the investigation continues, understanding the full scope and objectives of this operation remains crucial for enhancing defenses against future incidents.

The Hacker News Tags:APT, APT attack, Babuk ransomware, China, CVE-2026-59310, cyber attack, Cybersecurity, Exploitation, Ransomware, security flaw, vCenter, VMware, VMware vCenter Server, VMware vSphere, Vulnerability

Post navigation

Previous Post: MessiahGPT AI Model Threatens Security with Cybercrime Tools
Next Post: AI Agents Deploy Malware Amid Conflicting Goals

Related Posts

SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids The Hacker News
Why Default Passwords Must Go Why Default Passwords Must Go The Hacker News
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers The Hacker News
RustDuck Botnet Transformed in Rust for DDoS Attacks RustDuck Botnet Transformed in Rust for DDoS Attacks The Hacker News
Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads The Hacker News
Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chinese Hackers Impersonate Anthropic Staff to Target US AI Experts
  • Businesses Unprepared for AI and Quantum Security Risks
  • WordPress Backdoor Resists Removal with Reinfection Methods
  • WordPress Malware Resurfaces with Self-Healing Backdoor
  • AI Impacts Cyber Attack Speed, Fundamentals Remain Key

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chinese Hackers Impersonate Anthropic Staff to Target US AI Experts
  • Businesses Unprepared for AI and Quantum Security Risks
  • WordPress Backdoor Resists Removal with Reinfection Methods
  • WordPress Malware Resurfaces with Self-Healing Backdoor
  • AI Impacts Cyber Attack Speed, Fundamentals Remain Key

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark