CyberSecurity SEE

Suspected China-Nexus Actor Exploits VMware vCenter Vulnerability to Deploy Babuk-Derived Ransomware

Suspected China-Nexus Actor Exploits VMware vCenter Vulnerability to Deploy Babuk-Derived Ransomware

Cybersecurity Research Unveils Ongoing Threats Linked to CVE-2026-59310 and CVE-2026-59309

Cybersecurity researchers have recently identified a concerning exploitation of a security vulnerability in Broadcom’s VMware vCenter, specifically the CVE-2026-59310. This vulnerability, characterized as a severe directory-traversal flaw, holds a CVSS score of 9.8, indicating a high risk for exploitation. The research points towards a sophisticated group suspected to be an advanced persistent threat (APT) with potential ties to China.

The background to this incident lies in a patch that Broadcom released on July 29, 2026. However, it appears that cybercriminals swiftly moved to leverage this vulnerability within just a few days of its public disclosure. Experts from QUIRSO, a German incident response firm, have assessed the threat with moderate confidence, establishing that the attackers are likely Chinese-speaking individuals operating primarily in time zones that align with regions in China.

Details shared by QUIRSO researchers—Maike Orlikowski, Çağatay Yürekli, and Denis Szadkowski—indicate a pattern that supports this conclusion. They noted that various Chinese-language artifacts were detected within attacker-created scripts, a reuse of research found in publications from Chinese cybersecurity sources, and the use of tools and software management likely adapted from the Chinese language. Most notably, the group’s operational hours coincide with the UTC+08:00 time zone, further reinforcing the hypothesis of a Chinese nexus.

The exploitation campaign has yielded troubling statistics: approximately 361 unique victim IP addresses across 47 countries have been compromised. The geographical distribution of these attacks shows a significant concentration in Germany, the United States, Turkey, Iran, and France, signaling a widespread threat.

Dual Exploitations: CVE-2026-59309 and CVE-2026-59310

Adding to the complexity, it has been established that some compromised vCenter configurations faced assaults from both CVE-2026-59310 and CVE-2026-59309. This latter vulnerability presents an authentication bypass that has also seen active exploration by cybercriminals. Evidence suggests that exploit attempts for CVE-2026-59309 began as early as August 1, 2026, where it led to the creation of an unauthorized administrative account on vCenter.

Interestingly, inquiries revealed that no login events were logged for this new account, implying that its establishment served a more nefarious purpose rather than legitimate use. Analysis traced the account creation back to a specific IP address, which coordinated a sequence of discovery operations via the REST API, ultimately pointing to a sophisticated manipulation of vCenter’s functions.

Malicious Activity and Code Execution

The exploitation cycle for CVE-2026-59310 involved the cron daemon logging a particularly malformed file designed to facilitate further unlawful activities. It initiated a curl command to extract a backdoor from a specified IP address, thereby executing malevolent code. This backdoor, referred to as "linuxFile," was engineered for remote command execution, linking directly back to the attackers for real-time updates and instructions.

One of the more alarming aspects of this operation is its reliance on cron jobs for executing the payloads, including scripts from various compromised sources. The attackers were deliberate in their attempts to masquerade their actions as legitimate VMware activities, integrating commands that leveraged VMware’s configurations.

Furthermore, the attackers implemented several security measures to evade detection. For instance, malicious scripts were designed to change system files, facilitating unauthorized administrative access and allowing the attackers to manipulate settings without drawing suspicion.

Ransomware Deployment and Concluding Insights

Ultimately, this sequence of exploits led to a ransomware deployment on the compromised ESXi hosts, with files being encrypted under the ".babyk" extension, which is typically linked to Babuk-derived ransomware. While the ultimate intent behind this campaign remains uncertain, some experts posit that the ransomware deployment may have served as a distraction, obscuring the primary goals of espionage and system manipulation.

QUIRSO’s ongoing investigation has yet to ascertain if the ransomware was deployed across other infected systems, highlighting the need for continued vigilance in the face of evolving cyber threats. They suggest that the broader goal of the operations may not have solely focused on ransomware deployment, but rather on establishing a resilient foothold within the victims’ environments.

The researchers provided a stark reminder of the immediate implications of vulnerabilities such as CVE-2026-59310, emphasizing the importance of timely patches and proactive cybersecurity measures to defend against increasingly complex and furtive attacks.

In a follow-up to their analysis, QUIRSO discovered a GitHub repository associated with the threat actor, indicating an attempt to devise a tool for purging old files from temporary directories—potentially aimed at erasing evidence of their nefarious activity. This repository’s findings underscore the ongoing cat-and-mouse dynamics between cybersecurity defenders and sophisticated threat actors.

Overall, the recent findings collectively paint a grim portrait of contemporary cyber threats, necessitating an urgent reconsideration of cybersecurity protocols within vulnerable organizations.

Source link

Exit mobile version