No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Multiple Ransomware Groups Adapt Babuk Code to Target ESXi VMs

May 11, 2023
in Protection
0
Multiple Ransomware Groups Adapt Babuk Code to Target ESXi VMs



Over the past year, 10 different ransomware families have utilized leaked Babuk source code to develop lockers for VMware ESXi hypervisors.

Hypervisors are programs used to run multiple virtual machines (VMs) on a single server. By targeting ESXi, hackers may be able to infect multiple VMs in an enterprise environment more directly than they could through conventional means.

A few of the Babuk-based ESXi ransomwares are associated with major threat actors like Conti and REvil. And according to Alex Delamotte, senior threat researcher at SentinelOne, a majority of them have been utilized in real-world attacks in recent months.

“It looks like it’s an effective model,” says Delamotte, who published the new research this week. “As long as they stay profitable, hackers are going to keep using these lockers. And it does seem like they work.”

How We Got Here

Babuk was a popular though imperfect ransomware-as-a-service (RaaS) offering, first circulated in early 2021.

In September 2021, its business model was interrupted when one of the original creators had a moment of reckoning. “One of the developers for Babuk ransomware group, a 17 year old person from Russia, has been diagnosed with Stage-4 Lung Cancer,” vx-underground, a repository for malware source code, wrote in a tweet. “He has decided to leaked the ENTIRE Babuk source code for Windows, ESXI, NAS.”

Babuk As a Baseline

Since then, threat actors have been using Babuk’s various leaked tools as a baseline for crafting new malicious payloads.

For instance, in their report published May 4, researchers from Sentinel Labs identified significant overlaps between the Babuk ESXi ransomware builder and ten other ransomware families: Cylance, Dataf Locker, Lock4, Mario, Play, Rorschach, RTM Locker, XVGV, RHKRC — closely associated with the REvil group’s Revix locker — and “Conti POC” — a proof of concept from the notorious and now largely defunct ransomware group.

Delamotte says Mario, Rorschach, XVGV, and Conti POC have all been utilized in attacks already, and users on Bleeping Computer forums have reported being victim to Dataf Locker and Lock4.

Why Hackers Target ESXi

VMware ESXi, a “bare metal” hypervisor, uses no operating system as a buffer (“bare metal”), instead interfacing directly with logic hardware. It’s installed directly onto a physical server with unfettered access and control over the machine’s underlying resources.

All of this is what makes ESXi a powerful platform for IT administrators and, by the same token, hackers. Bad actors can aim to hit multiple VMs running on a single virtual server, utilizing “built-in tools for the ESXi hypervisor to kill guest machines, then encrypt crucial hypervisor files,” Delamotte explained in the report.

Enterprises running VMware’s ESXi need to be cautious, though the fix is straightforward.

“The most important thing is to ensure that any access — especially management access, to something like an ESXi hypervisor — is very limited,” Delamotte advises. “You want to have good role-based access controls and definitely MFA wherever possible on any service account.”

Strict, effective access controls should be enough to insulate the vulnerable. “I don’t really see any situation,” she says, “where somebody can move on to this kind of server without having admin privileges.”



Editorial Team

Editorial Team

Related Posts

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale
Protection

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale

March 25, 2026
Spotify's New 'SongDNA' Is Actually a Great Way to Learn More About Your Music
Protection

Spotify’s New ‘SongDNA’ Is Actually a Great Way to Learn More About Your Music

March 25, 2026
The Best Ways to Make Use of Those Spare USB Ports on Your TV or Monitor
Protection

The Best Ways to Make Use of Those Spare USB Ports on Your TV or Monitor

March 25, 2026
Ultrahuman’s New Ring Pro Is Finally Available in the US
Protection

Ultrahuman’s New Ring Pro Is Finally Available in the US

March 25, 2026
10 Shows Like 'Call the Midwife' You Should Watch Next
Protection

10 Shows Like ‘Call the Midwife’ You Should Watch Next

March 25, 2026
What The FCC's Router Ban Could Mean for You
Protection

What The FCC’s Router Ban Could Mean for You

March 25, 2026
Load More
Next Post
JD.com Shares Jump on Earnings Beat. The CEO Is Retiring.

JD.com Stock Jumps on Earnings Beat. The CEO Is Retiring.

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Time4Advice founders to retire as Richard Brian steps into leadership role

    0 shares
    Share 0 Tweet 0
  • How To Conduct A Productive Meeting

    0 shares
    Share 0 Tweet 0

Latest News

TAO hits four-month high as Bittensor halving draws more eyes now

TAO hits four-month high as Bittensor halving draws more eyes now

March 25, 2026
0

Bittensor’s native token TAO (TAO) moved higher on March 25 as traders tracked rising subnet activity, fresh staking data, and...

BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

March 25, 2026
0

BlackRock Chairman and CEO Larry Fink has an unforgiving message to private-credit investors who want to exit their funds.

BitGo and Susquehanna Crypto open OTC prediction markets to institutions

BitGo and Susquehanna Crypto open OTC prediction markets to institutions

March 25, 2026
0

BitGo Prime and Susquehanna Crypto have launched an institutional OTC offering that gives eligible BitGo clients access to listed prediction...

Oil prices fall on reports of a U.S. ceasefire proposal with Iran

Oil prices fall on reports of a U.S. ceasefire proposal with Iran

March 25, 2026
0

Brent crude traded 5% lower on reports of U.S. ceasefire proposal.

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.