Article

    Cyber News / Article / Ransomware attacks targeting VMware ESXi servers: everything you need to know

    Ransomware attacks targeting VMware ESXi servers: everything you need to know
    Me
    Merav Bar-2023-02-07

    Ransomware attacks targeting VMware ESXi servers: everything you need to know

    Recent attacks leverage CVE-2021-21974 to install ransomware on VMWare ESXi servers. Security teams are advised to patch and stay vigilant for indicators of compromise.

    On February 3rd, 2023, researchers began observing attacks aimed at the VMware ESXi hypervisor with the goal of infecting them with ransomware. The affected systems are ESXi hypervisors version 6.5, 6.7 and 7.0.

    These recent attacks, dubbedESXiArgs, leverage CVE-2021-21974, a vulnerability which impacts the Service Location Protocol (SLP) service and grants an attacker the ability to execute arbitrary code remotely. A patch has been available for CVE-2021-21974 since February 23rd, 2021.

    CVE-2021-21974is a heap overflow vulnerability in OpenSLP, a network service that listens on TCP and UDP port 427 on default installations of VMware ESXi. A malicious actor that has access to port 427 could exploit the heap overflow issue in the OpenSLP service, leading to remote code execution if the ESXi server is exposed to the internet.

    According to Wiz data, 12% of ESXi servers are currently unpatched for CVE-2021-21974 and vulnerable to attacks.

    Attacks utilizing this vulnerability to install ransomware have been discovered worldwide, though mostly in Europe. The targets of these attacks are primarily ESXi servers running versions prior to 7.0 U3i, which are accessible through the OpenSLP port 427.

    Researchers previously believed the malware, ESXiArgs, is an instance of theNevada ransomware family, which was first observed in December 2022 and associated with Chinese and Russian threat actors. As of February 8,further analysiscould indicate the malware might be a variant of theBabukransomware. Babuk source code was leaked in 2021 and utilized in previous ESXi ransomware attacks, such as CheersCrypt and PrideLocker encryptor from the Quantum/Dagon group.

    Researchers alsopublished a toolthat can assist with decrypting encrypted data, andCISA released a toolto attempt recovery of virtual machines affected by ESXiArgs.

    Since February 3rd, 2023,researchers have observedthe following IP addresses attempting to exploit CVE-2021-21974:

    Researchers alsoobservedthe following behaviors associated with this activity:

    ESXi versions7.xbefore ESXi70U1c-17325551

    ESXi versions6.7.xbefore ESXi670-202102401-SG

    ESXi versions6.5.xbefore ESXi650-202102101-SG

    Security teams are advised to patch VMware ESXi instances for CVE-2021-21974.

    As a workaround, you can also mitigate this issue by disabling the OpenSLP service, using the following commands:

    Wiz customers can use the pre-built query and advisory in the Wiz Threat Center to search for vulnerable instances in their VMWare ESXi servers.

    CERT-FR advisory

    Security Affairs article

    IPs observed by GreyNoise

    OVHCloud blog

    Twitter thread by researcher Habib Karatas

    Wiz's State of the Cloud 2023 report provides analysis of trends in cloud usage such as multi-cloud, use of managed services and more. In addition, the report highlights notable cloud risks based on insights from 30% of Fortune 100 enterprise cloud environments

    Learn Rego basics from Wiz to express policy as code for your cloud security.

    Simplify and centralize security and compliance management by sending audit-worthy events from Wiz into AWS CloudTrail Lake.

    Get a personalized demo

    ©2026Wiz, Inc.

    StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings

    Original source