No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

ESXi ransomware derived from Babuk code on the rise in early 2023

May 12, 2023
in Protection
0
ESXi ransomware derived from Babuk code on the rise in early 2023



There’s mounting evidence that ESXi hypervisors remain valuable targets for ransomware groups and that the leak of Babuk source code in September 2021 offered unprecedented insight for threat actors into the development operations of an organized ransomware group.

In a May 11 blog post, SentientlLabs reported that they observed a strong increase in VMware ESXi ransomware based on Babuk throughout early 2023.

However, Alex Delamotte, a SentinelOne threat researcher, said while other researchers claimed that Feburary’s ESXiArgs campaign on VMware servers was based on Babuk source code, SentinelOne’s analysis found that it’s unlikely because the only significant similarity between ESXiArgs and Babuk is that both use the same open-source libraries to implement the Sosemanuk stream cipher to encrypt files.

“The takeaway is that ESXi ransomware remains a popular target and the leaked Babuk source code enables actors of all skill levels to participate,” explained Delamotte. “The ESXiArgs campaign likely demonstrated the value and impact of ESXi lockers to a wider audience, which drove the increase in new Babuk-like variants through Q1 and Q2 2023.”

SentinelLabs said that over the past two years, organized ransomware groups adopted Linux lockers, including ALPHV, Black Basta, Conti, Lockbit and REvil. These groups focus on ESXi before other Linux variants, leveraging built-in tools for the ESXi hypervisor to kill guest machines, then encrypt crucial hypervisor files.

SentinelLabs also reported that it identified unexpected connections between ESXi ransomware families, exposing likely relationships between Babuk and better-known operations such as Conti and REvil. While ties to REvil remain tentative, the SentinelLabs researchers said the possibility exists that Babuk, Conti and REvil potentially outsourced an ESXi locker project to the same developer.

Companies are prime targets if they use ESXi and don’t have an accurate view into the version used, where those assets reside in their network, and if they face the public internet, said Dan Paulmeno, director of managed security services at Kivu Consulting.  

“In this case, a lot of ransomware crews that don’t normally target ESXi pounced on this opportunity because scanning and script deployment opportunities are trivial in comparison to enterprisewide attacks,” said Paulmeno.

This new information continues a trend of attacks on ESXi by cybercriminals looking for windfalls by compromising a host of hosts, said Craig Burland, chief information security officer at inversion6. Burland said the ESXiArgs attacks highlighted a big challenge with ESXi: timely patching. 

“Patching workloads related to a single application typically takes some negotiation between IT and the business owner,” Burland said. “Planning patches for ESXi immediately sparks 20 of those conversations and triggers the business to question the real risk of not applying every update.”

Mike Parkin, senior technical engineer at Vulcan Cyber, added that it’s always fascinating to get insight into how cybercriminal organizations operate both in how they function and how they develop code.  Parkin said it makes sense that other threat actors continued to develop the leaked Babuk code to suit their own needs. 

“While the Babuk leak may have hurt that specific group, it became an opportunity for other threat actors to incorporate new tools and techniques into their own attacks,” said Parking. “It becomes a challenge for defenders because even though we now have access to the original attack code, there will be more iterations of it that we’ll have to counter and the new variants will be harder to associate with a specific threat group.”

Editorial Team

Editorial Team

Related Posts

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale
Protection

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale

March 25, 2026
Spotify's New 'SongDNA' Is Actually a Great Way to Learn More About Your Music
Protection

Spotify’s New ‘SongDNA’ Is Actually a Great Way to Learn More About Your Music

March 25, 2026
The Best Ways to Make Use of Those Spare USB Ports on Your TV or Monitor
Protection

The Best Ways to Make Use of Those Spare USB Ports on Your TV or Monitor

March 25, 2026
Ultrahuman’s New Ring Pro Is Finally Available in the US
Protection

Ultrahuman’s New Ring Pro Is Finally Available in the US

March 25, 2026
10 Shows Like 'Call the Midwife' You Should Watch Next
Protection

10 Shows Like ‘Call the Midwife’ You Should Watch Next

March 25, 2026
What The FCC's Router Ban Could Mean for You
Protection

What The FCC’s Router Ban Could Mean for You

March 25, 2026
Load More
Next Post
Backlog in UK vetting poses national security risks, say MPs

Backlog in UK vetting poses national security risks, say MPs

Popular News

  • Condé Nast Traveler

    Why Cruise Fares Could Get More Expensive Amid the Iran War

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Time4Advice founders to retire as Richard Brian steps into leadership role

    0 shares
    Share 0 Tweet 0
  • How To Conduct A Productive Meeting

    0 shares
    Share 0 Tweet 0
  • DEAN DUNHAM: Is it legal for my hairdresser to charge me if I miss an appointment?

    0 shares
    Share 0 Tweet 0

Latest News

Enlivex adds 3B Rain tokens with $21M debt and $20M buyback - 1

Enlivex adds 3B Rain tokens with $21M debt and $20M buyback

March 25, 2026
0

Enlivex has raised $21 million through a debt financing deal as it expands its treasury tied to the prediction market...

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale

March 25, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Bernstein says Bitcoin bottom is in, reaffirms $150K year-end target

Bernstein says Bitcoin bottom is in, reaffirms $150K year-end target

March 25, 2026
0

Bernstein, the research and brokerage unit of AllianceBernstein, believes Bitcoin has found its cycle low and reiterates a $150,000 year-end...

Solana

Solana Foundation Launches Developer Platform — TradFi And DeFi Giants Join The Push

March 25, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The Solana Foundation announced on Tuesday the...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.