Suspected Chinese-speaking actors compromise 361 unique IP addresses, establish persistence, escalate privileges, and encrypt ESXi logs using Babuk-derived malware
According to research from German incident-response company QUIRSO, a suspected China-linked advanced persistent threat (APT) group has been exploiting a critical vulnerability in Broadcom’s VMware vCenter Server, reportedly compromising 361 unique IP addresses across 47 countries and delivering Babuk-derived ransomware.
The activity targeted internet-accessible vCenter systems and began only five days after Broadcom disclosed the flaw on 29 July 2026, with the first affected systems connecting to attacker infrastructure on 3 August 2026.
The vulnerability, tracked as CVE-2026-59310, affects the Syslog server component of VMware vCenter. It is a directory-traversal bug with a maximum CVSS severity score of 9.8, and an attacker with network access can exploit it to execute arbitrary code.
Broadcom has announced that no workaround is available, making installation of the appropriate security update the required remediation. Fixed releases include vCenter 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f, depending on the update branch.
Scale of attack estimated
QUIRSO has observed victims in 47 countries, with the largest numbers of unique IP addresses located in Germany, the United States, Turkey, Iran, and France. Those five countries represented 185 of the 361 identified addresses, although the researchers cautioned that IP counts do not necessarily equal the number of affected organizations because addresses can belong to cloud providers, hosting companies, or shared infrastructure. Other observation about the attack include:
- The campaign had expanded rapidly. Attackers first appeared on 3 August 2026, and 151 additional victim IP addresses were recorded the following day.
- By 5 August 2026, approximately 95% of the total observed addresses had been identified.
- The firm has assessed with moderate confidence that the operation was conducted by a Chinese-speaking actor operating in the UTC+08:00 time zone, citing Chinese-language artifacts, the use of Chinese tools, references to Chinese security research, working-hour patterns, and the absence of mainland Chinese victims.
- After gaining access, the attackers had installed reverse SSH tools to create persistent outbound connections. This allowed them to maintain remote access while potentially avoiding defenses focused on blocking unsolicited inbound traffic.
Shadowserver has announced that systems showing this persistence mechanism should be treated as fully compromised, although reverse SSH alone is a legitimate dual-use tool and must be assessed alongside other indicators.
The intrusion reportedly progressed to the creation of unauthorized administrator accounts on vCenter and ESXi hosts, privilege escalation using stolen VMware Directory Service credentials, and the deployment of ransomware on ESXi systems. The malware encrypted files with the .babyk extension and appeared related to the Babuk ransomware family. QUIRSO suspects the encryption may have been intended partly as a distraction, particularly because it targeted ESXi logs and could hinder forensic investigations.
QUIRSO later linked the activity to a GitHub repository created on 14 August 2026. The repository disguised reverse SSH binaries as a legitimate Linux temporary-file-cleaning utility, apparently helping attackers remove evidence from compromised machines. Administrators should consult Broadcom’s VMSA-2026-0006.1 advisory, apply the relevant patch immediately, and investigate for unauthorized cron entries, reverse SSH deployments, and unexpected outbound connections.
