Hackers compromise VMware vCenter systems in 47 countries
Attackers used CVE-2026-59310 to break into VMware vCenter systems and install tools that keep remote access. QUIRSO linked 361 victim IP addresses in 47 countries to the campaign, with the first known contacts on August 3. On August 17, QUIRSO said it suspects a Chinese-speaking group is responsible, found the same attacker also exploited a second vCenter flaw (CVE-2026-59309) on at least one system, and confirmed the attacker deployed Babuk-derived ransomware that encrypted files on at least one ESXi host. On August 18, CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to patch by August 21, 2026. Broadcom issued additional VMware Telco Cloud remediation guidance on September 1, 2026. No follow-up report confirms containment, compliance, or new victims. Victim organizations have not been named.
- Started
- Aug 3, 2026
- Latest activity
- Sep 1, 2026
- Attributed to
- China-linked (suspected, unnamed)Suspected
- Where
- Germany, United States, Turkey, Iran, France
- Sectors
- Multiple sectors
- Scale
- 361 victim IP addresses across 47 countries
Current status
No credible report or official statement dated after September 1, 2026 was found; the latest known update remains Broadcom's remediation guidance.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Who is behind it
QUIRSO's assessment (moderate confidence, based on Chinese-language artifacts, tool reuse, and victimology excluding mainland China) has not been confirmed or changed by any government agency; still an unnamed suspected group.
Impact
Attackers installed a scheduled task, a backdoor called linuxFile, and reverse SSH software to keep remote access to compromised vCenter systems. On at least one compromised system, the attacker deployed ransomware that encrypted ESXi host files with the .babyk extension. Researchers believe the ransomware may have been used to destroy log evidence and confuse investigators rather than as the main goal, but they could not rule out ransomware on other victims because their analysis only covered one system. The attacker also set up a GitHub repository disguised as a cleanup tool to erase traces of the intrusion and to distribute updated remote-access software. Federal agencies faced a mandatory patch deadline of August 21, 2026 under a binding CISA directive. No report confirms whether all agencies met it.
What to do
VMware vCenter administrators should install Broadcom's fixes for both CVE-2026-59310 and CVE-2026-59309, and check for unexpected scheduled tasks, new admin accounts such as "vcenter_admin," "adminuser," or "vcadmin," the file /etc/sudoers.d/vmware-perf, reverse SSH software, files named vmware-perf-update.jsp, and files with the .babyk extension on ESXi hosts. A patched vCenter server is not necessarily a clean one, so an indicator-of-compromise audit should accompany patching, especially for any system exposed to the internet between August 3 and August 18, 2026.
Timeline
-
Sep 1, 2026
Broadcom published VMware Telco Cloud remediation guidance for CVE-2026-59309 and CVE-2026-59310, listing fixed vCenter version 8.0 U3k.
Activeknowledge.broadcom.com -
Aug 20, 2026
Reporting detailed the campaign's speed, noting 151 additional victims appeared in a single 24-hour window on August 4 and about 95 percent of identified victims were compromised by August 5; no new attacker identity or victim names were disclosed.
Activetechtimes.com -
Aug 19, 2026
CISA urged immediate patching of the exploited VMware vCenter vulnerability along with other actively exploited Microsoft and Apple flaws.
Activesecurityweek.com -
Aug 18, 2026
CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog, along with three unrelated flaws in Apple macOS, Microsoft SharePoint, and Microsoft's Windows IKE service.
Activecisa.gov -
Aug 17, 2026
QUIRSO assessed with moderate confidence that a Chinese-speaking threat actor is behind the campaign, reported the same attacker also exploited a second vCenter flaw (CVE-2026-59309) on at least one system, and confirmed Babuk-derived ransomware encrypted ESXi host files on at least one victim.
Activethehackernews.com -
Aug 14, 2026
QUIRSO found a GitHub repository disguised as a Linux temp-file cleanup tool that was linked to the attacker's reverse SSH infrastructure and used to erase intrusion evidence and distribute updated remote-access binaries.
Activethehackernews.com -
Aug 13, 2026
BleepingComputer reported that the campaign remained active and was installing reverse SSH software for remote access. No new victim count or attacker was named.
Activebleepingcomputer.com -
Aug 12, 2026
Security reports said exploitation remained active and no attacker had been identified.
Activescworld.com -
Aug 10, 2026
QUIRSO reported 361 victim IP addresses across 47 countries and evidence of lasting remote access.
Activemedium.com -
Aug 3, 2026
The first identified compromised systems contacted attacker-controlled domains.
Activethehackernews.com -
Jul 29, 2026
Broadcom disclosed CVE-2026-59310 and released fixes for affected VMware vCenter versions.
support.broadcom.com
Sources
- VMSA-2026-0006.1: VMware updates address multiple vulnerabilities Broadcom Jul 29, 2026
- CVE-2026-59310 detail NVD Jul 30, 2026
- Active exploitation of CVE-2026-59310 across 47 countries QUIRSO Aug 10, 2026 unverified
- Critical VMware vCenter flaw actively exploited in 47 countries SC World Aug 12, 2026
- Attackers exploit VMware vCenter vulnerability to gain persistent remote access The Hacker News Aug 12, 2026
- Critical VMware vCenter RCE flaw exploited for reverse SSH access BleepingComputer Aug 13, 2026
- vCenter Flaw Exploited Just Five Days After Disclosure Infosecurity Magazine Aug 13, 2026
- Critical VMware vCenter Vulnerability in Attackers' Crosshairs SecurityWeek Aug 13, 2026
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware The Hacker News Aug 17, 2026
- CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities SecurityWeek Aug 19, 2026
- CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA Aug 18, 2026
- China Hackers Breached 361 Networks in 5 Days; CISA Sets 3-Day Patch Window for Enterprise Flaws Tech Times Aug 20, 2026
- That April Windows update you skipped? Hackers are exploiting it now PCWorld Aug 21, 2026
- VMware Telco Cloud response to VMSA-2026-0006 Broadcom Sep 1, 2026
Related reports
- VMware vCenter zero-day under attack Aug 12, 2026
- VMware vCenter bug can let attackers run code Aug 10, 2026