ESXiArgs
ESXiArgs is ransomware that targets VMware ESXi hypervisors.
Profile source: Mallory opens in a new tabESXiArgs
Family profile
ESXiArgs is ransomware that targets VMware ESXi hypervisors. It emerged prominently in early 2023 during a large-scale campaign against vulnerable, Internet-exposed ESXi servers. The malware encrypts critical ESXi and virtual machine files, including configuration and disk-related data, which can render hosted virtual machines unusable. It also creates companion metadata files for encrypted items and drops HTML ransom notes for victim communication and payment instructions.
Observed intrusions associated with ESXiArgs exploited CVE-2021-21974, a remote code execution vulnerability in the OpenSLP service on unpatched ESXi systems. Reporting also notes that exposed VMware vCenter infrastructure may be relevant in ESXi-focused intrusion chains. The campaign disproportionately affected organizations that had not applied available VMware patches or mitigations, and defensive guidance emphasized disabling SLP where patching had not yet occurred.
ESXiArgs is notable for focusing on virtualization infrastructure rather than conventional desktop endpoints, making it operationally disruptive because a single compromised hypervisor can impact many guest systems simultaneously. Analysis has discussed possible links to Babuk-derived ESXi lockers, but high-confidence comparative research found ESXiArgs was likely misattributed as Babuk-derived, with only limited similarity in use of a shared open-source cipher implementation rather than broader code lineage.
The malware is associated with opportunistic exploitation of exposed enterprise virtualization infrastructure and fits the broader trend of ransomware operators expanding from Windows environments to Linux-based and ESXi-focused targets.
Capabilities
- Exfiltration
- Initial Access
Operational record
Exploited software
Vulnerabilities linked to ESXiArgs
1 CVEsMITRE ATT&CK