CVE Tools

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

The Hacker NewsBy The Hacker News

Reported exploitedVMware vCenterBabuk

Our summary

A suspected Chinese state-aligned APT group is actively exploiting CVE-2026-59310, a critical directory traversal vulnerability in Broadcom's VMware vCenter Server, to establish root-level control over victim infrastructure. The campaign, which began shortly after the July 29, 2026 patch release, has compromised hundreds of servers across 47 countries, with researchers observing distinct Chinese-language artifacts and operational timing consistent with UTC+08:00.

Upon gaining access via the unauthenticated code execution flaw, attackers deploy a custom Linux implant and create backdoor accounts to maintain persistence. The intrusion culminates in the deployment of a Babuk-derived ransomware variant targeting ESXi hosts, although analysts suggest this may serve as a distraction to obscure broader espionage or sabotage activities.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store