- Several servers across 47 countries record a compromise via an exploit of Vmware vCenter directory-traversal flaw, with Chinese state-sponsored hackers as suspects.
- Threat actors deployed the custom linuxFile backdoor using cron jobs to establish persistent root access and execute remote commands.
- The campaign concluded by launching Babuk-derived ransomware on ESXi hypervisors to disrupt systems and destroy forensic event logs.
Recently, cybersecurity experts uncovered complex cyberattack operations against Broadcom VMware vCenter server products all over the globe. The attacks utilize a crucial flaw that allows hackers to run rogue code and infiltrate unprotected corporate networks.
QUIRSO, a German incident response firm, believes that a suspected Chinese-speaking advanced persistent threat group carried out the hacking campaign. The hackers managed to compromise hundreds of devices from the moment the vulnerability became public. Also, they started launching Babuk-based ransomware attacks against hypervisors.
Exploitation of Critical VMware Flaws and Unauthorized Account Creation
The campaign focuses on CVE-2026-59310, which is a critical vulnerability of directory traversal in VMware vCenter appliances and has a 9.8 CVSS score. On July 29, this year, Broadcom issued a fix for this vulnerability; however, cybercriminals started scanning and exploiting unprotected servers only five days after the details appeared publicly.
Researchers also identified the usage of CVE-2026-59309, a failure in authentication on compromised server appliances. The attackers used it in the exploit to create an administrative account in the VMware vCenter system without any authentication. Furthermore, the hackers set queries relating to vSphere management discovery features through REST API requests using spoofed User-Agent strings to hide within standard traffic.
Security specialists monitored the malicious traffic coming from suspicious IP addresses during early August. These initial probes aimed to map out enterprise infrastructure before launching follow-up intrusions. Nevertheless, the newly created administrator accounts served primarily as staging mechanisms for wider network reconnaissance across target organizations.
Deploying the LinuxFile Implant and Establishing Persistent Control
To exploit CVE-2026-59310, the attackers manipulated the system cron daemon by logging malformed configuration files. This clever technique trickled down into executing remote commands in a root context without needing privilege escalation. Consequently, the attackers fetched a backdoor known as linuxFile directly onto compromised systems.
The linuxFile implant establishes remote command execution capabilities by connecting to command-and-control servers via WebSocket channels. The malware decodes XOR-obfuscated network addresses at run-time and uses custom application-layer cryptography to hide commands. Additionally, the backdoor sets up automatic reconnection routines and systemd services to ensure persistent access.
Attackers also scheduled several cron jobs disguised as legitimate VMware background services. These scheduled tasks dropped JSP web shells, extracted administrative credentials, and added unauthorized user accounts to the vSphere SSO Administrators group. Furthermore, the hackers granted unrestricted sudo permissions to local service accounts to cement root access.
Regional Victimology and the Broader Threat Landscape
The campaign has affected at least 361 unique victim IP addresses across 47 different countries. Germany had the biggest share of the attacks, with 55 compromised servers, and the United States following closely with 41 infections. Other heavily impacted nations include Turkey, Iran, and France.
The international nature of this campaign mirrors a separate takedown operation targeting pro-Russia hacktivists. Spanish National Police, acting on an FBI tip, arrested a man in Palencia suspected of collaborating with Cyber Army of Russia Reborn and NoName057 to facilitate attacks against critical infrastructure in the U.S. and Europe.
Analysts confirmed the threat actor operates primarily within the UTC+08:00 time zone based on working hours and Chinese-language scripts. Furthermore, the attacker used Chinese management software while carefully avoiding targets within mainland China.
The ultimate phase of the attack involved deploying a Babuk-derived ransomware locker on ESXi hosts. The malware encrypts virtual machine files and appends the .babyk file extension across affected storage volumes.
Ransomware Deployment Used as a Smokescreen for Network Distraction
According to the researchers, deploying file-encrypting malware is not necessarily the primary purpose of this espionage campaign. In reality, the threat agent might have utilized the ransomware derived from the Babuk technology as a means of misleading incident response teams and hindering forensic investigations.
By encrypting the logs from the ESXi host, these cybercriminals basically destroyed vital telemetry information that security people require to get details about the intrusion.
Also, by encrypting virtual machines, the hackers forced security groups to concentrate on their immediate recovery instead of tracking the unobservable data theft process. The combination of state-sponsored espionage means and commercial ransomware is a tactical move that makes threat attribution a complicated process. Further, it illustrates how advanced groups may utilize open-source malware to hide their real intentions.
According to Broadcom, all VMware vCenter administrators should apply the official security patch as soon as possible to avoid unauthorized access. Companies should also check their local cron directories and audit their administrator access for any unauthorized accounts.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
WhatsApp Tests On-Device Scam Alert without Reading User Messages
WhatsApp is testing a new tool called Scam Alert that spots scam messages right on your phone. The t...
Apple Faces Lawsuit Over Claims that iCloud Private Relay Leaks User IP Addresses
A law firm sued Apple, saying its Private Relay tool did not protect user privacy as promised. Exper...
Hackers Exploit TrueConf Servers to Distribute Malware Through Fake Software Updates
A hacker group named Head Mare broke into TrueConf video meeting servers and swapped safe installers...
New NatJack Attack Exposes Hidden Weakness in How Networks Handle Internet Connections
Security researcher Malcolm Stagg has uncovered NatJack, a new class of attacks that exploits a fund...
Germany Warns Companies Over Missing Security Contact Files on Most Websites
Germany’s cyber agency BSI wants every website to publish a security.txt file so researchers c...
TP-Link Patches 15 Omada Flaws that could Let Hackers Compromise Entire Networks
TP-Link fixed a total of 15 vulnerabilities in the ZTP solution that powers its Omada networking eco...