Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io
Cloud Threat Landscape

Ransomware operators exploit ESXi vulnerability

Type
Campaign
Actors
🌩️Storm-0506🌩️Storm-1175🦭Manatee Tempest🐙0ktapus
Pub. date
July 29, 2024
Initial access
1-day vulnerability
Impact
RansomOp
Observed techniques
Vulnerability exploitationNetwork lateral movementCredential theftValid creds abuse
Observed tools
QakbotBlackBasta ransomwareCobalt StrikePypikatzSystemBC
Targeted technologies
ESXi Server
References
https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/
Status
Finalized
Last edited
Sep 22, 2024 10:52 AM

Microsoft researchers have discovered a vulnerability in ESXi hypervisors, identified as CVE-2024-37085. This flaw is being exploited by ransomware operators to gain full administrative access to domain-joined ESXi hypervisors, enabling them to encrypt file systems, access hosted virtual machines, and move laterally within networks. The vulnerability stems from a default configuration issue that allows members of a domain group named "ESX Admins" to have full administrative privileges. It is recommended to update ESXi to the most recent versions.

The vulnerability involves a group named "ESX Admins," which, if created or renamed in an Active Directory domain, grants its members full administrative access to domain-joined ESXi hypervisors. This occurs due to a lack of validation by ESXi hypervisors, which incorrectly grant such access based on the group name rather than a security identifier (SID).

The vulnerability can be exploited through several methods, including creating the "ESX Admins" group, renaming an existing group to "ESX Admins," or exploiting delayed privilege refresh in ESXi. This flaw has been used in attacks by ransomware operators such as Storm-0506 and Storm-1175, leading to ransomware deployments like Akira and Black Basta.

Made with 💙 by Wiz

Last Updated: April 3, 2025