Ethical Hacking News
A recently patched vulnerability in VMware vCenter has been exploited by a suspected China-nexus advanced persistent threat actor, leading to the deployment of Babuk-derived ransomware on ESXi hosts. The attack highlights the importance of timely patching and vulnerability management, and serves as a reminder of the sophistication and coordination that can be seen in advanced persistent threat attacks.
VMware vCenter was exploited by a malicious attack that leaves numerous organizations vulnerable to data breaches. A China-nexus advanced persistent threat (APT) actor is suspected of the attack, linked to the exploitation of CVE-2026-59310. The attack began after the public disclosure of the vulnerability in July 2026, approximately five days later. The attack is sophisticated, using multiple entry points to breach security posture, and linked to other vulnerabilities in VMware vCenter. The attack deployed Babuk-derived ransomware, encrypting files with the ".babyk" extension. The attack highlights the importance of timely patching and vulnerability management.
The cybersecurity landscape has recently been hit with a malicious attack that exploits a recently patched vulnerability in VMware vCenter, leaving numerous organizations vulnerable to potential data breaches. According to cybersecurity researchers, a suspected China-nexus advanced persistent threat (APT) actor has been linked to the exploitation of CVE-2026-59310, a severe directory-traversal vulnerability that can be weaponized by a malicious actor to execute arbitrary code.
The attack began to manifest itself approximately five days after the public disclosure of the vulnerability in July 2026. Researchers from German incident response company QUIRSO assessed with moderate confidence that the exploitation campaign aimed at CVE-2026-59310 is operated by a Chinese-speaking threat actor, likely working in the UTC+08:00 time zone, which is predominantly used in Chinese-speaking regions.
The suspected China-nexus actor has been linked to the exploitation of CVE-2026-59310, CVE-2026-59309, and other vulnerabilities in VMware vCenter. This suggests that the attack is sophisticated and well-coordinated, utilizing multiple entry points to breach the security posture of its victims.
The attack involved the exploitation of CVE-2026-59310, which allowed the threat actor to execute arbitrary code on the vCenter server appliance. The attackers then used the cron daemon to execute malicious payloads, including a backdoor that was used to establish persistence on the system. The threat actor also created multiple administrative accounts, including a "vcenter_admin" account, which was used to gain unauthorized access to the system.
The attack ultimately paves the way for the deployment of a ransomware on ESXi hosts that encrypts files with the ".babyk" extension, which is typically associated with Babuk-derived ransomware. While it is unclear whether the ransomware was deployed across other compromised systems, the attack has significant implications for organizations that use VMware vCenter.
The use of CVE-2026-59310 by the suspected China-nexus actor is a stark reminder of the importance of timely patching and vulnerability management. The fact that the vulnerability was recently patched in July 2026 and yet still managed to be exploited by the threat actor highlights the need for organizations to prioritize their patching and vulnerability management processes.
In conclusion, the recent attack that exploits CVE-2026-59310 and deploys Babuk-derived ransomware is a significant threat to organizations that use VMware vCenter. The attack highlights the importance of timely patching and vulnerability management and serves as a reminder of the sophistication and coordination that can be seen in advanced persistent threat attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Suspected-Chinese-Nexus-Actor-Exploits-VMware-vCenter-Flaw-Deploys-Babuk-Derived-Ransomware-ehn.shtml
https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html
https://nvd.nist.gov/vuln/detail/CVE-2026-59310
https://www.cvedetails.com/cve/CVE-2026-59310/
https://nvd.nist.gov/vuln/detail/CVE-2026-59309
https://www.cvedetails.com/cve/CVE-2026-59309/
Published: Mon Aug 17 06:45:52 2026 by llama3.2 3B Q4_K_M