Skip to content

ESXiArgs

ESXiArgs is ransomware that targets VMware ESXi hypervisors and became widely known during a large-scale campaign in early 2023 affecting exposed, unpatched servers across multiple countries, particularly in Europe and North America.

Profile source: Mallory opens in a new tab

ESXiArgs

Family profile

ESXiArgs is ransomware that targets VMware ESXi hypervisors and became widely known during a large-scale campaign in early 2023 affecting exposed, unpatched servers across multiple countries, particularly in Europe and North America. The campaign has been associated with exploitation of CVE-2021-21974, a remote code execution flaw in the ESXi OpenSLP service, allowing attackers to compromise vulnerable internet-facing hosts and deploy the locker without authentication.

Once executed, ESXiArgs encrypts ESXi and virtual machine-related files, including configuration and disk files, which can render hosted virtual machines unusable and disrupt many business services at once. It also creates per-file metadata used during encryption and leaves ransom notes for victims. Analysis indicates the binary itself is relatively simple and depends on operator-supplied parameters and external scripting to iterate over target files. The malware requires the path to an RSA public key file as an argument and uses the Sosemanuk cipher implementation in its encryption workflow. Like other ESXi-focused ransomware, it is intended for enterprise server environments rather than consumer endpoints.

ESXiArgs is notable for targeting virtualization infrastructure, where a single compromised hypervisor can impact numerous guest systems simultaneously. Public reporting initially speculated that it was derived from Babuk, but later comparative analysis found little meaningful similarity beyond limited overlap such as use of the same cipher implementation, making strong lineage claims unsupported. Recovery tooling was released for some victims, though later variants were reported that were not recoverable with the initial script.

Capabilities

  • Exfiltration
  • Initial Access

Operational record

1
YARA rules
1
Ransom notes

Exploited software

Vulnerabilities linked to ESXiArgs

1 CVEs

MITRE ATT&CK

ESXiArgs in ATT&CK

11 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.