{"id":1947,"date":"2026-08-19T07:23:11","date_gmt":"2026-08-19T00:23:11","guid":{"rendered":"https:\/\/vncybers.vn\/ho-so-chien-dich-vmware-vcenter-nhom-nghi-lien-he-trung-quoc-babuk\/"},"modified":"2026-08-19T07:25:42","modified_gmt":"2026-08-19T00:25:42","slug":"vmware-vcenter-campaign-china-nexus-babuk-ransomware-profile-2","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/ho-so-chien-dich-vmware-vcenter-nhom-nghi-lien-he-trung-quoc-babuk\/","title":{"rendered":"VMware vCenter Campaign Profile: Suspected China-Nexus Actor and Babuk-Derived Ransomware"},"content":{"rendered":"<p>A new campaign targeting VMware vCenter shows how threat actors can turn a core infrastructure flaw into a path for takeover, persistence and ransomware deployment across virtualized environments. According to The Hacker News, researchers at QUIRSO assess with moderate confidence that the activity exploiting CVE-2026-59310 is linked to a Chinese-speaking actor, likely operating in the UTC+08:00 time zone.<\/p>\n<p>The important point is not only the 9.8 CVSS vulnerability. It is the post-exploitation chain: creating administrator accounts, installing backdoors, using cron and systemd for persistence, deploying reverse SSH, placing web shells, collecting vCenter credentials and ultimately enabling Babuk-derived ransomware on ESXi hosts.<\/p>\n<p style=\"text-align: center;\"><img fetchpriority=\"high\" decoding=\"async\" width=\"719\" height=\"674\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/08\/vmware-babuk-inline.jpg\" alt=\"Technical diagram of the VMware vCenter exploitation campaign based on The Hacker News reporting\" class=\"wp-image-1945\" style=\"max-width: 100%; height: auto;\" srcset=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/08\/vmware-babuk-inline.jpg 719w, https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/08\/vmware-babuk-inline-300x281.jpg 300w, https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/08\/vmware-babuk-inline-13x12.jpg 13w\" sizes=\"(max-width: 719px) 100vw, 719px\" \/><\/p>\n<h2>Campaign background<\/h2>\n<p>Broadcom released a fix for CVE-2026-59310 on July 29, 2026. The flaw is a directory traversal vulnerability in VMware vCenter Server that can be abused for remote code execution. According to QUIRSO, exploitation activity began about five days after details of the issue became public.<\/p>\n<p>The Hacker News cited earlier analysis saying the campaign affected 361 unique victim IP addresses across 47 countries. Germany, the United States, Turkey, Iran and France were among the countries with the highest observed victim counts. That distribution suggests a broad exploitation campaign rather than an isolated intrusion.<\/p>\n<h2>Attribution signals and actor profile<\/h2>\n<p>QUIRSO did not name a specific group, but it highlighted several signals pointing toward a China-linked actor: Chinese-language artifacts in attacker-created scripts, apparent reuse of research from a Chinese security publication, repeated use of Chinese-language tools and management software, victimology excluding mainland China and activity patterns compatible with UTC+08:00 working hours.<\/p>\n<p>This kind of attribution should be treated carefully. In cybersecurity, language, tooling and time zone data are probability signals, not absolute proof. Still, when several independent indicators converge, they help defenders understand the likely operating model, target selection and technical maturity of the adversary.<\/p>\n<h2>The vCenter intrusion chain<\/h2>\n<p>On one analyzed vCenter Server Appliance, QUIRSO observed evidence related to both CVE-2026-59310 and CVE-2026-59309. For CVE-2026-59309, the attacker appears to have created a new vCenter administrator account and used a User-Agent such as <strong>GoodMoodle-VCFleet\/1.0<\/strong> to make vSphere discovery traffic look related to VMware Cloud Foundation.<\/p>\n<p>For CVE-2026-59310, the first observed activity involved cron logging a malformed file named <strong>zz-poc59310-syslog.log<\/strong>. A later curl or wget command downloaded a backdoor from attacker infrastructure and removed traces. The filename suggests rapid weaponization of public proof-of-concept details after disclosure.<\/p>\n<h2>Backdoors, persistence and administrator control<\/h2>\n<p>The implant known as <strong>linuxFile<\/strong> can receive remote commands over a WebSocket channel, execute them through <strong>\/bin\/sh<\/strong> and send results back to command infrastructure. Its C2 address is XOR-obfuscated and decoded at runtime, while communications use the malware's own application-layer cryptography despite relying on unencrypted ws transport.<\/p>\n<p>The actor also relied heavily on cron to download scripts, deploy architecture-specific reverse SSH binaries, drop a JSP web shell, add SSH keys to authorized keys, create vSphere accounts such as <strong>adminuser<\/strong> and <strong>vcadmin<\/strong>, while granting passwordless sudo access to the service account: <strong>perfcharts<\/strong>. These steps point to long-term control, not merely one-time code execution.<\/p>\n<h2>Babuk-derived ransomware may be a smokescreen<\/h2>\n<p>The final observed stage involved ransomware on ESXi hosts, encrypting files with the extension: <strong>.babyk<\/strong>, a marker commonly associated with Babuk-derived variants. QUIRSO has not concluded that ransomware was necessarily the main goal of the campaign.<\/p>\n<p>One important possibility is that the ransomware was used as a smokescreen to disrupt analysis, destroy ESXi logs and reduce forensic visibility into earlier activity. If so, encryption damage may be only the visible surface, while the deeper objective could involve persistence, credential theft or longer-term espionage preparation.<\/p>\n<h2>Defensive lessons for enterprises<\/h2>\n<p>VMware vCenter is a sensitive control point for virtualized infrastructure. Once vCenter is compromised with root or administrator-level access, attackers can reach ESXi hosts, service accounts, vSphere APIs and other critical management layers. Patching therefore needs to be paired with compromise assessment, not treated as the end of the response.<\/p>\n<p>Organizations should review newly created administrator accounts, unusual cron and systemd entries, unknown JSP files, new SSH keys, local ESXi accounts, unexpected sudo rules, reverse SSH connections and User-Agents that mimic VMware components. For exposed systems, rotating vCenter credentials and checking vmdir integrity should be treated as high-priority tasks.<\/p>\n<h2>Conclusion<\/h2>\n<p>This VMware vCenter campaign is a reminder that flaws in infrastructure management platforms can create blast effects far beyond a single server. When an actor combines fast exploitation, legitimate administration tools, layered persistence and Babuk-derived ransomware, defenders need to investigate the entire virtualization environment, not only restore encrypted machines.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from The Hacker News and QUIRSO<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>This VMware vCenter exploitation campaign shows how a suspected China-nexus actor gained persistence, escalated control and deployed Babuk-derived ransomware on ESXi.<\/p>","protected":false},"author":2,"featured_media":1946,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[70],"tags":[653,657,655,652,651,654,656,658,650,114],"class_list":["post-1947","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ho-so","tag-babuk","tag-broadcom-vmware","tag-china-nexus-apt","tag-cve-2026-59309","tag-cve-2026-59310","tag-esxi-ransomware","tag-quirso","tag-reverse-ssh","tag-vmware-vcenter","tag-vncybers"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=1947"}],"version-history":[{"count":2,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1947\/revisions"}],"predecessor-version":[{"id":1949,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1947\/revisions\/1949"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/1946"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=1947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=1947"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=1947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}