• About
  • Privacy & Policy
  • Contact
Today Headline
  • HOME
  • NEWS
    • POLITICS
  • FINANCE
  • Video
  • ENTERPRISE
  • TECHNOLOGY
  • HEALTH
  • ENTERTAINMENT
  • LIFESTYLE
    • TRAVEL
  • AUTOMOTIVE
  • SPORTS
  • HOME
  • NEWS
    • POLITICS
  • FINANCE
  • Video
  • ENTERPRISE
  • TECHNOLOGY
  • HEALTH
  • ENTERTAINMENT
  • LIFESTYLE
    • TRAVEL
  • AUTOMOTIVE
  • SPORTS
No Result
View All Result
TodayHeadline
No Result
View All Result
Home Enterprise

Ransomware gangs are abusing VMWare ESXi exploits to encrypt virtual hard disks

February 2, 2021
in Enterprise
0
Ransomware gangs are abusing VMWare ESXi exploits to encrypt virtual hard disks
0
SHARES
12
VIEWS
Share on FacebookShare on Twitter


cloud-provider-stopped-ransomware-attack-5f158ee1ef2c1c64094a991b-1-jul-23-2020-14-40-19-poster.jpg

At least one major ransomware gang is abusing vulnerabilities in the VMWare ESXi product to take over virtual machines deployed in enterprise environments and encrypt their virtual hard drives.

The attacks, first seen last October, have been linked to intrusions carried out by a criminal group that deployed the RansomExx ransomware.

According to multiple security researchers who spoke with ZDNet, evidence suggests the attackers used CVE-2019-5544 and CVE-2020-3992, two vulnerabilities in VMware ESXi, a hypervisor solution that allows multiple virtual machines to share the same hard drive storage.

Both bugs impact the Service Location Protocol (SLP), a protocol used by devices on the same network to discover each other; also included with ESXi.

The vulnerabilities allow an attacker on the same network to send malicious SLP requests to an ESXi device and take control of it, even if the attacker has not managed to compromise the VMWare vCenter server to which the ESXi instances usually report to.

In attacks that have taken place last year, the RansomExx gang has been seen gaining access to a device on a corporate network and abusing this initial entry point to attack local ESXi instances and encrypt their virtual hard disks, used to store data from across virtual machines, causing massive disruptions to companies, as ESXi virtual disks are usually used to centralize data from multiple other systems.

Reports of these attacks have been documented on Reddit, shared on Twitter, presented at a security conference last month, and confirmed in interviews with ZDNet over the past two months.

Free threat intel – identify and patch VMware ESX vulnerabilities CVE-2019-5544 and CVE-2020-3992.

Ransomware group using them to bypass all Windows OS security, by shutting down VMs and encrypting the VMDK’s directly on hypervisor.

— Kevin Beaumont (@GossiTheDog) November 7, 2020

For now, only the RansomExx (also known as Defray777) gang has been seen abusing this trick, but in a mysterious update last month, the operator of the Babuk Locker ransomware has also announced an eerily similar feature —although successful attacks have not yet been confirmed.

System administrators at companies that rely on VMWare ESXi to manage the storage space used by their virtual machines are advised to either apply the necessary ESXi patches or disable SLP support to prevent attacks if the protocol isn’t needed.

 
 
   
Previous Post

Angelina Jolie stars in contemporary western film Those Who Wish Me Dead set for May release date

Next Post

Fight over fees led to Trump’s last minute legal-team switch up

Next Post
Fight over fees led to Trump’s last minute legal-team switch up

Fight over fees led to Trump's last minute legal-team switch up

  • Trending
  • Comments
  • Latest
Schoolgirl’s ‘unimaginable’ final hours and how her earring put killer on Death Row

Schoolgirl’s ‘unimaginable’ final hours and how her earring put killer on Death Row

February 28, 2021
Notorious gang leader shot dead and 400 inmates escape during prison break

Notorious gang leader shot dead and 400 inmates escape during prison break

February 27, 2021
Diamond-tipped probe used to fix faulty heart rhythms could cut the risk of stroke

Diamond-tipped probe used to fix faulty heart rhythms could cut the risk of stroke

March 2, 2021
PS5 UK restocks TODAY – Live alerts for GAME, Currys, Very, Amazon, Argos stock drops | Gaming | Entertainment

PS5 UK restocks TODAY – Live alerts for GAME, Currys, Very, Amazon, Argos stock drops | Gaming | Entertainment

March 2, 2021

Many Generation Xers in UK face financial hardship in retirement | Retirement planning

March 2, 2021
Majorcan estate where Richard Branson will build ‘the most luxurious hotel in the Mediterranean’ 

Majorcan estate where Richard Branson will build ‘the most luxurious hotel in the Mediterranean’ 

March 3, 2021
John Oates revives music festival to help fight pandemic-related hunger crisis

John Oates revives music festival to help fight pandemic-related hunger crisis

March 3, 2021

Bitcoin and Robinhood will end badly for those who can least afford it | Stock markets

March 3, 2021
‘Now I can try and deal with it’ – NZ star Stott reveals cancer diagnosis – FTBL | The home of football in Australia – The Women’s Game

‘Now I can try and deal with it’ – NZ star Stott reveals cancer diagnosis – FTBL | The home of football in Australia – The Women’s Game

March 3, 2021

Burst Water Main Floods Street in Alexandria, Virginia

March 3, 2021

About Us

Todayheadline the independent news and topics discovery
A home-grown and independent news and topic aggregation . displays breaking news linking to news websites all around the world.

Follow Us

Latest News

Majorcan estate where Richard Branson will build ‘the most luxurious hotel in the Mediterranean’ 

Majorcan estate where Richard Branson will build ‘the most luxurious hotel in the Mediterranean’ 

March 3, 2021
John Oates revives music festival to help fight pandemic-related hunger crisis

John Oates revives music festival to help fight pandemic-related hunger crisis

March 3, 2021
Majorcan estate where Richard Branson will build ‘the most luxurious hotel in the Mediterranean’ 

Majorcan estate where Richard Branson will build ‘the most luxurious hotel in the Mediterranean’ 

March 3, 2021
John Oates revives music festival to help fight pandemic-related hunger crisis

John Oates revives music festival to help fight pandemic-related hunger crisis

March 3, 2021

Bitcoin and Robinhood will end badly for those who can least afford it | Stock markets

March 3, 2021
  • About
  • Privacy & Policy
  • Contact

© 2019 All rights are reserved Todayheadline

No Result
View All Result
  • About Us
  • Contact Us
  • Cookie policy (EU)
  • Home
  • Privacy Policy
  • Video

© 2019 All rights are reserved Todayheadline