LIVE
LATEST THREAT: China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware THREAT ALERT ACTIVE
Intelligence DB / Campaign Alert Babuk-derived (.babyk)

China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware

A suspected China-nexus threat actor weaponized CVE-2026-59310, a critical vCenter directory-traversal flaw, within five days of patch release, compromising 361 IPs across 47 countries and deploying Babuk-derived ransomware on ESXi hosts.

By Ransomware Tracker ·
vmwarevcenteresxivulnerability-exploitationchina-nexusbabukcve-2026-59310
Threat Level
9/10
Sectors Targeted
technology
higher education
telecommunications
research
cybersecurity
Ransomware Family
Babuk-derived (.babyk)

Rapid weaponization of a critical vCenter flaw

A suspected China-nexus advanced persistent threat group has been linked to a fast-moving exploitation campaign against Broadcom VMware vCenter Server, culminating in the deployment of Babuk-derived ransomware on compromised ESXi hosts. The campaign is notable less for the ransomware payload itself and more for the speed and scale of exploitation: attackers began weaponizing the flaw just five days after Broadcom shipped a patch.

The vulnerability at the center of the campaign, CVE-2026-59310, is a directory-traversal flaw in vCenter’s Syslog server rated 9.8 on the CVSS scale, allowing arbitrary remote code execution with no available workaround. A second flaw, CVE-2026-59309, an authentication bypass, was also incorporated into the attack chain. Broadcom released patches for both issues on July 29, 2026. Exploitation activity tied to CVE-2026-59309 was observed as early as August 1, with vSphere discovery activity following on August 3 and a sharp escalation in compromised infrastructure — 343 of the eventual 361 victim IPs — logged by August 5.

Scale: 361 victims across 47 countries

Researchers tracked 361 unique victim IP addresses spanning 47 countries. Germany recorded the highest concentration of compromised systems (55), followed by the United States (41), Turkey (38), Iran (26), and France (25). Sector analysis pointed to disproportionate exposure among technology, software, cybersecurity, higher education, research, and telecommunications organizations — a pattern consistent with internet-facing vCenter appliances that were exposed and unpatched when exploitation began.

Attack chain: root access, backdoors, and persistence

After exploiting CVE-2026-59310 to execute commands as root on vCenter Server Appliances, the operators deployed a custom backdoor tracked as “linuxFile” (also observed as systemlog/linux_x86), which communicates over WebSocket for remote command execution. Persistence was established through malformed cron entries and systemd units, and the attackers created new administrative accounts to maintain access independent of the initial exploit. Reverse SSH binaries provided a secondary channel for sustained outbound access, and credential harvesting was used to pivot toward follow-on compromise of connected ESXi hosts.

On at least some compromised ESXi environments, files were partially encrypted and renamed with the “.babyk” extension — a signature associated with Babuk-derived ransomware code, which has circulated in leaked form since 2021 and been repurposed by multiple unrelated actors and groups over the years, including Ra World and other regional operators. Researchers assess that ransomware deployment may not have been the campaign’s primary objective; the scale and sophistication of the backdoor infrastructure, combined with the absence of victims inside mainland China, points toward a broader espionage or access-brokering motive with opportunistic encryption layered on top.

Attribution

German incident response firm QUIRSO attributed the campaign to a Chinese-speaking threat actor operating in the UTC+08:00 timezone with “moderate confidence.” The assessment rests on Chinese-language artifacts embedded in attacker scripts, reuse of tooling previously documented in Chinese-language security research publications, and the conspicuous absence of victims located in mainland China — a common pattern researchers use to infer state-nexus or state-tolerated activity.

Why this matters for ransomware defenders

This campaign illustrates a trend Ransomware Tracker has flagged repeatedly in 2026: the line between espionage-oriented APT activity and ransomware deployment continues to blur. Babuk’s leaked builder has now been recycled by everything from financially motivated RaaS affiliates to, apparently, state-nexus operators using encryption as a secondary or diversionary payload after establishing durable backdoor access. Organizations running internet-facing vCenter infrastructure should treat this incident as a reminder that patch timelines for hypervisor management planes need to be measured in hours, not weeks — attackers here had a working exploit chain within five days of disclosure and had compromised hundreds of targets within eleven.

Recommendations

  • Patch vCenter Server Appliances against CVE-2026-59310 and CVE-2026-59309 immediately if not already done.
  • Do not assume patching alone remediates exposure — hunt for existing compromise, since the attackers established persistence via cron, systemd, and rogue admin accounts that survive patching.
  • Audit cron jobs, systemd units, and local admin/service accounts on vCenter appliances for unauthorized entries.
  • Restrict internet-facing access to vCenter management interfaces; place them behind VPN or jump-host access with MFA.
  • Monitor for the “linuxFile” backdoor, reverse SSH tooling, and files renamed with the “.babyk” extension on connected ESXi hosts.
  • Review outbound network connections from vCenter and ESXi hosts for anomalous WebSocket or reverse-shell traffic.

Sources

// Related Intelligence
Campaign Alert

Cl0p's Next Platform: Custom Web Shell Hits PTC Windchill and FlexPLM

Campaign Alert

FortiBleed Credentials Are Fuelling INC Ransom and Lynx Ransomware Attacks

Campaign Alert

Akira's SonicWall Campaign: How a VPN Appliance Became a Gateway to 100+ Intrusions