Feb. 6, 2023, 2:30 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


European cybersecurity authorities are warning of “massive active network exploitation” of an almost 2-year-old VMWare ESXi vulnerability by ransomware actors.


The campaign is being named ESXiArgs because the ransomware creates an additional file with the extension .args after encrypting a document. The file contains information about how to decrypt the victim document, researchers say.


Thousands of servers in Europe and North America have already been compromised, according to Censys searches for systems displaying a ransom note.


As VMWare describes ESXi, …

america campaign censys compromised cybersecurity decrypt document esxi esxiargs esxiargs ransomware europe exploitation extension file information network north north america old ransomware researchers searches servers victim vmware vmware esxi vulnerability warning

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC