No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Multiple Ransomware Groups Adapt Babuk Code to Target ESXi VMs

May 11, 2023
in Protection
0
Multiple Ransomware Groups Adapt Babuk Code to Target ESXi VMs



Over the past year, 10 different ransomware families have utilized leaked Babuk source code to develop lockers for VMware ESXi hypervisors.

Hypervisors are programs used to run multiple virtual machines (VMs) on a single server. By targeting ESXi, hackers may be able to infect multiple VMs in an enterprise environment more directly than they could through conventional means.

A few of the Babuk-based ESXi ransomwares are associated with major threat actors like Conti and REvil. And according to Alex Delamotte, senior threat researcher at SentinelOne, a majority of them have been utilized in real-world attacks in recent months.

“It looks like it’s an effective model,” says Delamotte, who published the new research this week. “As long as they stay profitable, hackers are going to keep using these lockers. And it does seem like they work.”

How We Got Here

Babuk was a popular though imperfect ransomware-as-a-service (RaaS) offering, first circulated in early 2021.

In September 2021, its business model was interrupted when one of the original creators had a moment of reckoning. “One of the developers for Babuk ransomware group, a 17 year old person from Russia, has been diagnosed with Stage-4 Lung Cancer,” vx-underground, a repository for malware source code, wrote in a tweet. “He has decided to leaked the ENTIRE Babuk source code for Windows, ESXI, NAS.”

Babuk As a Baseline

Since then, threat actors have been using Babuk’s various leaked tools as a baseline for crafting new malicious payloads.

For instance, in their report published May 4, researchers from Sentinel Labs identified significant overlaps between the Babuk ESXi ransomware builder and ten other ransomware families: Cylance, Dataf Locker, Lock4, Mario, Play, Rorschach, RTM Locker, XVGV, RHKRC — closely associated with the REvil group’s Revix locker — and “Conti POC” — a proof of concept from the notorious and now largely defunct ransomware group.

Delamotte says Mario, Rorschach, XVGV, and Conti POC have all been utilized in attacks already, and users on Bleeping Computer forums have reported being victim to Dataf Locker and Lock4.

Why Hackers Target ESXi

VMware ESXi, a “bare metal” hypervisor, uses no operating system as a buffer (“bare metal”), instead interfacing directly with logic hardware. It’s installed directly onto a physical server with unfettered access and control over the machine’s underlying resources.

All of this is what makes ESXi a powerful platform for IT administrators and, by the same token, hackers. Bad actors can aim to hit multiple VMs running on a single virtual server, utilizing “built-in tools for the ESXi hypervisor to kill guest machines, then encrypt crucial hypervisor files,” Delamotte explained in the report.

Enterprises running VMware’s ESXi need to be cautious, though the fix is straightforward.

“The most important thing is to ensure that any access — especially management access, to something like an ESXi hypervisor — is very limited,” Delamotte advises. “You want to have good role-based access controls and definitely MFA wherever possible on any service account.”

Strict, effective access controls should be enough to insulate the vulnerable. “I don’t really see any situation,” she says, “where somebody can move on to this kind of server without having admin privileges.”



Editorial Team

Editorial Team

Related Posts

This Substack Data Breach May Have Compromised Nearly 700,000 User Records
Protection

This Substack Data Breach May Have Compromised Nearly 700,000 User Records

February 6, 2026
Blink's Highly Rated Wired Floodlight Camera Is Just $45 Right Now
Protection

Blink’s Highly Rated Wired Floodlight Camera Is Just $45 Right Now

February 6, 2026
AirDrop Is Coming to Even More Android Phones This Year
Protection

AirDrop Is Coming to Even More Android Phones This Year

February 6, 2026
Spotify's 'About the Song' Feature Uses AI to Tell You the Meaning Behind Your Favorite Songs
Protection

Spotify’s ‘About the Song’ Feature Uses AI to Tell You the Meaning Behind Your Favorite Songs

February 6, 2026
I Tried Malwarebytes' ChatGPT App, and It's Actually Good at Detecting Scams
Protection

I Tried Malwarebytes’ ChatGPT App, and It’s Actually Good at Detecting Scams

February 6, 2026
The Samsung Galaxy Watch 8 Is $200 Off Right Now
Protection

The Samsung Galaxy Watch 8 Is $200 Off Right Now

February 6, 2026
Load More
Next Post
JD.com Shares Jump on Earnings Beat. The CEO Is Retiring.

JD.com Stock Jumps on Earnings Beat. The CEO Is Retiring.

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • 11 Best Affordable Hotels in Rome (2024)

    0 shares
    Share 0 Tweet 0
  • What The Clarity Act Means For Ripple And XRP Once Done

    0 shares
    Share 0 Tweet 0
  • Apple Card vs. Chase Sapphire Preferred: Tried-and-True Sapphire Wins Again

    0 shares
    Share 0 Tweet 0

Latest News

Condé Nast Traveler

The Best Fado Bars in Lisbon, According to Portuguese Singer Carminho

February 6, 2026
0

“Lisbon is the city of fado,” says Portuguese singer Carminho. “You have to experience it when you're there.”Carminho, who recently...

Sui Network partners with Coinbase as exchange adopts Sui token standard

Sui Network partners with Coinbase as exchange adopts Sui token standard

February 6, 2026
0

Sui Network, a high-performance layer-1 blockchain platform, and Coinbase, a leading crypto exchange, announced a partnership today to expand institutional...

NFL heads into Super Bowl after season of record ratings, paving way for TV-rights bonanza

NFL heads into Super Bowl after season of record ratings, paving way for TV-rights bonanza

February 6, 2026
0

The NFL hopes that Sunday’s Super Bowl LX between the Seattle Seahawks and New England Patriots will top last year’s...

This Substack Data Breach May Have Compromised Nearly 700,000 User Records

This Substack Data Breach May Have Compromised Nearly 700,000 User Records

February 6, 2026
0

When you sign up for a subscription on Substack, you're thinking you'll receive newsletters and posts from online creators, not...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.