{"id":2366,"date":"2026-08-17T11:49:04","date_gmt":"2026-08-17T11:49:04","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2366"},"modified":"2026-08-17T11:49:04","modified_gmt":"2026-08-17T11:49:04","slug":"suspected-china-nexus-actor-exploits-vmware-vcenter-flaw-deploys-babuk-derived-ransomware","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2366","title":{"rendered":"Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhN5GzIjo1DOb9leWRsG7hi5zemNCi6kb_NBf-391nF9pphXhTgf8DZLMlk-fUyp-j4rT_cFv4coBpP821rfQkUc4ydAu5YQBcn9Y6nj-SeQGDNu10DmSN2JYDmWJTzLUSXsvDYPTBQ_cQkkCFAIkdMCyRgRv5YIPdMgkp62BtqaYE49b3aWnm4QbYM7YeK\/s1700-e365\/vmware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT).<\/p>\n<p>The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code. A fix for the flaw was released by Broadcom on July 29, 2026.<\/p>\n<p>German incident response company QUIRSO assessed with moderate confidence that the exploitation campaign aimed at CVE-2026-59310 is operated by a Chinese-speaking threat actor, likely working in the UTC+08:00 time zone, which is predominantly used in Chinese-speaking regions.<\/p>\n<p>\u00abThis assessment is based on the convergence of Chinese-language artifacts in attacker-created scripts, apparent reuse of research from a Chinese security publication, repeated operational use of Chinese-language tools and management software, victimology excluding mainland China, and activity patterns compatible with UTC+08:00 working hours,\u00bb QUIRSO researchers Maike Orlikowski, \u00c7a\u011fatay Y\u00fcrekli, and Denis Szadkowski <a href=\"https:\/\/medium.com\/@quirso_de\/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d\" target=\"_blank\">said<\/a>.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The activity, which commenced five calendar days after public disclosure of the flaw, is estimated to have compromised 361 unique victim IP addresses across 47 countries, with most of the infections scattered across Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).<\/p>\n<h3>Exploitation of CVE-2026-59309<\/h3>\n<p>One compromised vCenter Server Appliance analyzed by QUIRSO is said to have been targeted by both CVE-2026-59310 and CVE-2026-59309, an authentication bypass that has also witnessed active scanning efforts. Evidence shows malicious activity consistent with the exploitation of CVE-2026-59309 as early as August 1, 2026, followed by the creation of an administrative account on vCenter.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>That said, no login events have been observed for the legitimate administrative account that was used to create this new account. The account creation originated from the IP address 146.59.252[.]178 and also involved vSphere discovery via the REST API on August 3 using User-Agent strings like \u00abGoodMoodle-VCFleet\/1.0,\u00bb in an attempt to masquerade it as VMware-related activity.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhajL3nYK_NaB1_4FHCQiy54x3ACwgvL3H2Fw9rx6AgA0mB72Pik-Pz-bGWB7Yv0sHzFNM5XZUt30MbLrY1FdWS9QyimITYbcDTSWrcY1iPWthNkqG2fDeD9lQlSBFZ01_hSBNd9WArO4Awn-1YMrbfwE-BeNny2PhrpLwOsbHhnPg9cF9nZUJ4jQaYmwyv\/s1700-e365\/q.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhajL3nYK_NaB1_4FHCQiy54x3ACwgvL3H2Fw9rx6AgA0mB72Pik-Pz-bGWB7Yv0sHzFNM5XZUt30MbLrY1FdWS9QyimITYbcDTSWrcY1iPWthNkqG2fDeD9lQlSBFZ01_hSBNd9WArO4Awn-1YMrbfwE-BeNny2PhrpLwOsbHhnPg9cF9nZUJ4jQaYmwyv\/s1700-e365\/q.jpg\" alt=\"\" border=\"0\" data-original-height=\"674\" data-original-width=\"719\"\/><\/a><\/div>\n<p>It&#8217;s worth noting that VCF Fleet is a centralized management capability introduced by Broadcom in ware Cloud Foundation (VCF) in version 9.0 to deploy, scale, patch, and operate multiple VCF instances. It encompasses multiple components, including VCF Operations, VCF Automation, vCenter, NSX Manager, vSphere Cluster, and workload domains.<\/p>\n<p>QUIRSO said there is no overlap between this activity and the chain of events involving the abuse of CVE-2026-59310 on the same system starting August 3, adding the newly created \u00abvcenter_admin\u00bb administrator account was not used in subsequent phases of the attack.<\/p>\n<h3>Exploitation of CVE-2026-59310<\/h3>\n<p>As for the exploitation of CVE-2026-59310, the first activity involved the cron daemon (aka crond) logging a malformed cron file called \u00abzz-poc59310-syslog.log.\u00bb In the next step, a curl command (or alternatively a wget command) is executed to retrieve a backdoor from \u00ab5.34.177[.]38:9861\u00bb and execute it, and then remove the log file.<\/p>\n<p>The naming convention of the log file is significant as it is a direct reference to the CVE identifier and that it was a proof-of-concept (PoC) devised after details of the flaw became public knowledge.<\/p>\n<p>\u00abThe &#8216;-syslog.log&#8217; suffix also mirrors the vCSA remote syslog file naming convention, but the file appears under \/etc\/cron.d rather than the configured syslog output directory,\u00bb QUIRSO explained. \u00abThis suggests that the vCSA syslog server was abused to place files in a privileged execution location. While some files were malformed and not executed by cron, at least one file successfully executed and placed the &#8216;linuxFile&#8217; backdoor on the system.\u00bb<\/p>\n<p>The linuxFile implant is designed to provide remote command execution capabilities to the attacker. It establishes a connection to its controller over a WebSocket channel to receive instructions, executes them through \/bin\/sh, and transmits the results back to the attacker.<\/p>\n<p>\u00abThe C2 [command-and-control] address is XOR-obfuscated and decoded at run-time, while communications are protected using the malware&#8217;s own application-layer cryptography despite using an unencrypted ws:\/\/ transport,\u00bb Szadkowski told The Hacker News via email. \u00abIt also automatically reconnects on failure and contains routines for establishing persistence through systemd and cron.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The threat actor behind the operation also relied extensively on cron to execute malicious payloads, including to fetch and run a shell script (\u00abesxi.sh\u00bb) from the IP address \u00ab185.144.28[.]120:3232.\u00bb The shell script then serves as a downloader and persistence installer for an architecture-specific reverse SSH (\u00abreverse_ssh\u00bb) binary that&#8217;s retrieved from the same infrastructure.<\/p>\n<p>Other cron jobs related to creating staging directories, downloading executables, changing their permissions, and running them, while referencing servers at \u00ab192.255.141[.]13:8080\u00bb and \u00ab5.34.176[.]100:5244.\u00bb In what appears to be an operational security blunder, the latter has been found to expose the reverse SSH binaries toolset via an AList directory listing.<\/p>\n<p>A brief description of some of the various actions carried out by the threat actor is as follows &#8211;<\/p>\n<ul>\n<li>Deploying \u00ablinuxFile\u00bb (aka systemlog or linux_x86), which connects to \u00abws:\/\/intel.se9ly9upbhay.shop:8080\/ws\u00bb and establishes persistence via a systemd service.<\/li>\n<li>Setting three cronjobs impersonating legitimate VMware services: vmware-vpxd-stats-* (facilitates an SSH-based remote access channel by adding the attacker&#8217;s SSH public key to the authorized keys file), vmware-perf-collect-* (drops a JSP web shell named \u00abvmware-perf-update.jsp\u00bb), and vmware-perf-sync-* (drops the same web shell and runs a Base64-encoded script that performs credential access and sets up a new account called \u00abadminuser,\u00bb which is then added to the vSphere SSO Administrators group.<\/li>\n<li>Creating two additional accounts: adding \u00abvcadmin\u00bb to vSphere with a Base64-encoded Python script dropped on disk via bash commands run in a cronjob and creating a vSphere admin account via an external LDAP \u00abAdd\u00bb operation against vCenter&#8217;s VMware Directory Service (vmdir) from a remote client by using a pre-existing but compromised administrative account.<\/li>\n<li>Creating a file named \u00ab\/etc\/sudoers.d\/vmware-perf\u00bb with a configuration that grants the \u00abperfcharts\u00bb service account unrestricted, non-interactive passwordless sudo access to root.<\/li>\n<li>Running shell scripts like \u00ab\/tmp\/.vmware-perf-upd.sh\u00bb to obtain credentials for vmdir by querying the HKEY_THIS_MACHINE\\services\\vmdir registry location. If this method fails, it searches for VMware&#8217;s vmafd Python module and calls GetMachineName(), GetMachinePassword(), and GetDomainName() to get the distinguished name and password associated with the vCenter machine account. The stolen credentials are used to conduct privileged directory modifications, including adding the aforementioned \u00abadminuser\u00bb identity to the Administrators group.<\/li>\n<li>Using vSphere API to perform discovery operations and \u00abesxi.sh\u00bb to deploy the reverse_ssh client.<\/li>\n<li>Creating local accounts on the ESXi hosts (e.g., \u00abadminuser\u00bb) to enable ransomware encryption.<\/li>\n<li>Taking steps to evade detection, reduce forensic visibility, and blend into the VMware environment.<\/li>\n<\/ul>\n<p>The attack ultimately paves the way for the deployment of a ransomware on ESXi hosts that encrypts files with the \u00ab.babyk\u00bb extension, which is typically associated with Babuk-derived ransomware. It&#8217;s not clear if this was the end goal of the campaign, or if the Babuk-derived payload was \u00abselected opportunistically or even intentionally\u00bb to confuse attribution efforts.<\/p>\n<p>QUIRSO told the publication it cannot assess at this stage if the ransomware strain was deployed across other compromised systems as the analysis was limited to only one of the infected systems. However, based on the investigation so far, it&#8217;s suspected that the deployment of the locker may not have been the primary objective of the campaign.<\/p>\n<p>Szadkowski likened the deployment to a smokescreen engineered to distract defenders from the main intrusion and thwart analysis by encrypting the ESXi log files, thereby preventing access to telemetry data that could have offered more insights into threat actor activity.<\/p>\n<p>\u00abExploitation of CVE-2026-59310 provided the actor with immediate, non-interactive code execution in a root context on the vCenter Server appliance,\u00bb the researchers said. \u00abSubsequent commands recorded by CROND were therefore already being executed as root, giving the actor unrestricted access to the underlying VCSA without first having to compromise an unprivileged local account and escalate from it.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2367,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[172,3022,2369,297,430,70,93,2368,3012,409],"class_list":["post-2366","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-actor","tag-babukderived","tag-chinanexus","tag-deploys","tag-exploits","tag-flaw","tag-ransomware","tag-suspected","tag-vcenter","tag-vmware"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2366"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2366\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2367"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}