No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Multiple Ransomware Groups Adapt Babuk Code to Target ESXi VMs

May 11, 2023
in Protection
0
Multiple Ransomware Groups Adapt Babuk Code to Target ESXi VMs



Over the past year, 10 different ransomware families have utilized leaked Babuk source code to develop lockers for VMware ESXi hypervisors.

Hypervisors are programs used to run multiple virtual machines (VMs) on a single server. By targeting ESXi, hackers may be able to infect multiple VMs in an enterprise environment more directly than they could through conventional means.

A few of the Babuk-based ESXi ransomwares are associated with major threat actors like Conti and REvil. And according to Alex Delamotte, senior threat researcher at SentinelOne, a majority of them have been utilized in real-world attacks in recent months.

“It looks like it’s an effective model,” says Delamotte, who published the new research this week. “As long as they stay profitable, hackers are going to keep using these lockers. And it does seem like they work.”

How We Got Here

Babuk was a popular though imperfect ransomware-as-a-service (RaaS) offering, first circulated in early 2021.

In September 2021, its business model was interrupted when one of the original creators had a moment of reckoning. “One of the developers for Babuk ransomware group, a 17 year old person from Russia, has been diagnosed with Stage-4 Lung Cancer,” vx-underground, a repository for malware source code, wrote in a tweet. “He has decided to leaked the ENTIRE Babuk source code for Windows, ESXI, NAS.”

Babuk As a Baseline

Since then, threat actors have been using Babuk’s various leaked tools as a baseline for crafting new malicious payloads.

For instance, in their report published May 4, researchers from Sentinel Labs identified significant overlaps between the Babuk ESXi ransomware builder and ten other ransomware families: Cylance, Dataf Locker, Lock4, Mario, Play, Rorschach, RTM Locker, XVGV, RHKRC — closely associated with the REvil group’s Revix locker — and “Conti POC” — a proof of concept from the notorious and now largely defunct ransomware group.

Delamotte says Mario, Rorschach, XVGV, and Conti POC have all been utilized in attacks already, and users on Bleeping Computer forums have reported being victim to Dataf Locker and Lock4.

Why Hackers Target ESXi

VMware ESXi, a “bare metal” hypervisor, uses no operating system as a buffer (“bare metal”), instead interfacing directly with logic hardware. It’s installed directly onto a physical server with unfettered access and control over the machine’s underlying resources.

All of this is what makes ESXi a powerful platform for IT administrators and, by the same token, hackers. Bad actors can aim to hit multiple VMs running on a single virtual server, utilizing “built-in tools for the ESXi hypervisor to kill guest machines, then encrypt crucial hypervisor files,” Delamotte explained in the report.

Enterprises running VMware’s ESXi need to be cautious, though the fix is straightforward.

“The most important thing is to ensure that any access — especially management access, to something like an ESXi hypervisor — is very limited,” Delamotte advises. “You want to have good role-based access controls and definitely MFA wherever possible on any service account.”

Strict, effective access controls should be enough to insulate the vulnerable. “I don’t really see any situation,” she says, “where somebody can move on to this kind of server without having admin privileges.”



Editorial Team

Editorial Team

Related Posts

The LG 27GX700A-B Ultragear Is 41% Off Right Now
Protection

The LG 27GX700A-B Ultragear Is 41% Off Right Now

February 6, 2026
The Top 10 TV Series in January 2026, According to Streaming Data
Protection

The Top 10 TV Series in January 2026, According to Streaming Data

February 6, 2026
These Sony Over-Ear Headphones Come in Three Colors and Are Under $100 Right Now
Protection

These Sony Over-Ear Headphones Come in Three Colors and Are Under $100 Right Now

February 6, 2026
A Sling One-Day Pass Is the Best Way to Catch a Major Sporting Event Without Cable
Protection

A Sling One-Day Pass Is the Best Way to Catch a Major Sporting Event Without Cable

February 6, 2026
The TCL QM5K Was Already Affordable, and Now It's an Extra $450 Off
Protection

The TCL QM5K Was Already Affordable, and Now It’s an Extra $450 Off

February 5, 2026
What to Do If Your Car Icon Disappears From Google Maps in Android Auto
Protection

What to Do If Your Car Icon Disappears From Google Maps in Android Auto

February 5, 2026
Load More
Next Post
JD.com Shares Jump on Earnings Beat. The CEO Is Retiring.

JD.com Stock Jumps on Earnings Beat. The CEO Is Retiring.

Popular News

  • Hargreaves Lansdown hits 2m clients and record AUA

    Hargreaves Lansdown hits 2m clients and record AUA

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • I Used Monarch Money for 30 Days: Here’s What Happened

    0 shares
    Share 0 Tweet 0
  • My brother, a corporate lawyer, refuses to sell our family’s $175K lake house. Do I push the issue and risk ruining our relationship?

    0 shares
    Share 0 Tweet 0
  • As Jamie Dimon stakes his reputation, are more banks about to fall?

    0 shares
    Share 0 Tweet 0

Latest News

Elliot Wave points to a Dogecoin price rebound as DOGE ETF inflows rise

Dogecoin, Shiba Inu slid deeper as on-chain activity spike

February 6, 2026
0

Dogecoin and Shiba Inu slid deeper into selloff territory even as on-chain activity spiked, underscoring a growing disconnect between network...

Oil extends decline ahead of US-Iran talks

Oil extends decline ahead of US-Iran talks

February 6, 2026
0

Oil extends decline ahead of US-Iran talks

The LG 27GX700A-B Ultragear Is 41% Off Right Now

The LG 27GX700A-B Ultragear Is 41% Off Right Now

February 6, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Crypto Fear and Greed Index sinks to 9 after $2.7B in leveraged erased

Crypto Fear and Greed Index sinks to 9 after $2.7B in leveraged erased

February 6, 2026
0

Crypto traders faced one of the most brutal resets on Thursday after Bitcoin’s free fall wiped out roughly $2.7 billion...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.