A large-scale ESXiArgs ransomware campaign hit internet-exposed VMware ESXi servers by exploiting a long-known vulnerability in the OpenSLP service, with incident responders and national authorities warning that many affected systems had not applied available patches. CERT-FR issued an alert on active exploitation affecting VMware ESXi, while broad reporting described widespread compromises across organizations globally as attackers encrypted virtual machine files and dropped ransom notes on hypervisors.
VMware said the attacks did not stem from a newly discovered zero-day, but from exploitation of older, already patched weaknesses and insecurely exposed services on unsupported or unpatched ESXi versions. The incident renewed scrutiny of VMware security after earlier warnings that threat actors, including state-backed operators, had abused VMware flaws such as CVE-2020-4006 for initial access, persistence, and privileged movement inside enterprise environments, underscoring the risk posed by internet-facing virtualization infrastructure that lags on patching and hardening.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
SC Media reported that a trio of VMware ESXi zero-day vulnerabilities had been chained in attacks long before they were publicly disclosed. The report introduced a later attribution and technical-development update to the broader ESXi exploitation story.
VMware Security Response Center issued an official response to the ESXiArgs attacks, providing guidance and context on the ransomware activity affecting ESXi servers. This marked VMware's public response following the widespread exploitation reports.
CERT-FR and BleepingComputer reported a large-scale campaign exploiting a VMware ESXi vulnerability to compromise exposed, unpatched servers worldwide. The activity was associated with the ESXiArgs ransomware attacks.
The NSA disclosed that Russian state-sponsored attackers were actively exploiting CVE-2020-4006 to compromise VMware systems, install web shells, and pivot into Active Directory and ADFS environments. The advisory described the activity as affecting multiple victims.
VMware released a fix for CVE-2020-4006, a command-injection flaw in VMware products, after being notified by the NSA. Ars Technica reports the patch was issued the Thursday before 2020-12-07.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceblogs.vmware.com
Open sourcebleepingcomputer.com
Open sourcecert.ssi.gouv.fr
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.