Skip to content

ESXiArgs

ESXiArgs is ransomware that targets VMware ESXi hypervisors.

Profile source: Mallory opens in a new tab

ESXiArgs

Family profile

ESXiArgs is ransomware that targets VMware ESXi hypervisors. It emerged prominently in early 2023 during a large-scale campaign against vulnerable, Internet-exposed ESXi servers. The malware encrypts critical ESXi and virtual machine files, including configuration and disk-related data, which can render hosted virtual machines unusable. It also creates companion metadata files for encrypted items and drops HTML ransom notes for victim communication and payment instructions.

Observed intrusions associated with ESXiArgs exploited CVE-2021-21974, a remote code execution vulnerability in the OpenSLP service on unpatched ESXi systems. Reporting also notes that exposed VMware vCenter infrastructure may be relevant in ESXi-focused intrusion chains. The campaign disproportionately affected organizations that had not applied available VMware patches or mitigations, and defensive guidance emphasized disabling SLP where patching had not yet occurred.

ESXiArgs is notable for focusing on virtualization infrastructure rather than conventional desktop endpoints, making it operationally disruptive because a single compromised hypervisor can impact many guest systems simultaneously. Analysis has discussed possible links to Babuk-derived ESXi lockers, but high-confidence comparative research found ESXiArgs was likely misattributed as Babuk-derived, with only limited similarity in use of a shared open-source cipher implementation rather than broader code lineage.

The malware is associated with opportunistic exploitation of exposed enterprise virtualization infrastructure and fits the broader trend of ransomware operators expanding from Windows environments to Linux-based and ESXi-focused targets.

Capabilities

  • Exfiltration
  • Initial Access

Operational record

1
YARA rules
1
Ransom notes

Exploited software

Vulnerabilities linked to ESXiArgs

1 CVEs

MITRE ATT&CK

ESXiArgs in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.