China-Linked Hackers Exploit VMware Flaw to Deploy Babuk Ransomware (2026)

The recent exploitation of a critical security flaw in Broadcom VMware vCenter has raised concerns about the involvement of a suspected China-nexus advanced persistent threat (APT). This incident highlights the ongoing threat landscape and the need for robust cybersecurity measures.

The vulnerability, CVE-2026-59310, carries a CVSS score of 9.8, indicating its severity. It allows a malicious actor to execute arbitrary code, posing a significant risk to affected systems. The flaw was promptly addressed by Broadcom with a patch released on July 29, 2026.

German incident response company QUIRSO assessed the situation with moderate confidence, attributing the exploitation campaign to a Chinese-speaking threat actor. The assessment is based on a range of indicators, including the use of Chinese-language artifacts, research from Chinese security publications, and operational tools and management software in the Chinese language. The victimology, excluding mainland China, further supports this attribution.

The attack, which began five days after the public disclosure of the flaw, compromised 361 unique victim IP addresses across 47 countries. Germany, the U.S., Turkey, Iran, and France were among the most affected nations. QUIRSO's analysis revealed that the compromised vCenter Server Appliance was targeted by both CVE-2026-59310 and CVE-2026-59309, an authentication bypass vulnerability.

The threat actor employed a range of techniques to establish a foothold on the compromised systems. They utilized cron jobs to execute malicious payloads, including the retrieval and execution of a backdoor from a specific IP address. The naming convention of log files, referencing the CVE identifier, indicated a proof-of-concept approach.

QUIRSO's investigation uncovered the actor's extensive use of cron to execute commands, such as fetching and running a shell script from another IP address. This script served as a downloader and persistence installer for a reverse SSH binary. The actor also created administrative accounts, modified system configurations, and performed discovery operations using vSphere APIs.

One of the most concerning aspects of this attack is the deployment of Babuk-derived ransomware on ESXi hosts. The ransomware encrypts files with the '.babyk' extension, typically associated with the Babuk ransomware family. The attribution of this ransomware to the Babuk group raises questions about the actor's intentions and the potential impact on attribution efforts.

In conclusion, this incident highlights the ongoing threat posed by advanced persistent threats and the need for proactive cybersecurity measures. The involvement of a suspected China-nexus actor underscores the complexity of the threat landscape and the importance of continuous vigilance and threat intelligence.

China-Linked Hackers Exploit VMware Flaw to Deploy Babuk Ransomware (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Delena Feil

Last Updated:

Views: 6565

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Delena Feil

Birthday: 1998-08-29

Address: 747 Lubowitz Run, Sidmouth, HI 90646-5543

Phone: +99513241752844

Job: Design Supervisor

Hobby: Digital arts, Lacemaking, Air sports, Running, Scouting, Shooting, Puzzles

Introduction: My name is Delena Feil, I am a clean, splendid, calm, fancy, jolly, bright, faithful person who loves writing and wants to share my knowledge and understanding with you.