Active Critical impact Espionage Checked 1d ago

Hackers compromise VMware vCenter systems in 47 countries

Attackers used CVE-2026-59310 to break into VMware vCenter systems and install tools that keep remote access. QUIRSO linked 361 victim IP addresses in 47 countries to the campaign, with the first known contacts on August 3. On August 17, QUIRSO said it suspects a Chinese-speaking group is responsible, found the same attacker also exploited a second vCenter flaw (CVE-2026-59309) on at least one system, and confirmed the attacker deployed Babuk-derived ransomware that encrypted files on at least one ESXi host. On August 18, CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to patch by August 21, 2026. Broadcom issued additional VMware Telco Cloud remediation guidance on September 1, 2026. No follow-up report confirms containment, compliance, or new victims. Victim organizations have not been named.

Started
Aug 3, 2026
Latest activity
Sep 1, 2026
Attributed to
China-linked (suspected, unnamed)Suspected
Where
Germany, United States, Turkey, Iran, France
Sectors
Multiple sectors
Scale
361 victim IP addresses across 47 countries

Current status

No credible report or official statement dated after September 1, 2026 was found; the latest known update remains Broadcom's remediation guidance.

Active: Confirmed and still going. Attacker activity or disruption is continuing.

Who is behind it

QUIRSO's assessment (moderate confidence, based on Chinese-language artifacts, tool reuse, and victimology excluding mainland China) has not been confirmed or changed by any government agency; still an unnamed suspected group.

Impact

Attackers installed a scheduled task, a backdoor called linuxFile, and reverse SSH software to keep remote access to compromised vCenter systems. On at least one compromised system, the attacker deployed ransomware that encrypted ESXi host files with the .babyk extension. Researchers believe the ransomware may have been used to destroy log evidence and confuse investigators rather than as the main goal, but they could not rule out ransomware on other victims because their analysis only covered one system. The attacker also set up a GitHub repository disguised as a cleanup tool to erase traces of the intrusion and to distribute updated remote-access software. Federal agencies faced a mandatory patch deadline of August 21, 2026 under a binding CISA directive. No report confirms whether all agencies met it.

What to do

VMware vCenter administrators should install Broadcom's fixes for both CVE-2026-59310 and CVE-2026-59309, and check for unexpected scheduled tasks, new admin accounts such as "vcenter_admin," "adminuser," or "vcadmin," the file /etc/sudoers.d/vmware-perf, reverse SSH software, files named vmware-perf-update.jsp, and files with the .babyk extension on ESXi hosts. A patched vCenter server is not necessarily a clean one, so an indicator-of-compromise audit should accompany patching, especially for any system exposed to the internet between August 3 and August 18, 2026.

Timeline

  1. Sep 1, 2026

    Broadcom published VMware Telco Cloud remediation guidance for CVE-2026-59309 and CVE-2026-59310, listing fixed vCenter version 8.0 U3k.

    Activeknowledge.broadcom.com
  2. Aug 20, 2026

    Reporting detailed the campaign's speed, noting 151 additional victims appeared in a single 24-hour window on August 4 and about 95 percent of identified victims were compromised by August 5; no new attacker identity or victim names were disclosed.

    Activetechtimes.com
  3. Aug 19, 2026

    CISA urged immediate patching of the exploited VMware vCenter vulnerability along with other actively exploited Microsoft and Apple flaws.

    Activesecurityweek.com
  4. Aug 18, 2026

    CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog, along with three unrelated flaws in Apple macOS, Microsoft SharePoint, and Microsoft's Windows IKE service.

    Activecisa.gov
  5. Aug 17, 2026

    QUIRSO assessed with moderate confidence that a Chinese-speaking threat actor is behind the campaign, reported the same attacker also exploited a second vCenter flaw (CVE-2026-59309) on at least one system, and confirmed Babuk-derived ransomware encrypted ESXi host files on at least one victim.

    Activethehackernews.com
  6. Aug 14, 2026

    QUIRSO found a GitHub repository disguised as a Linux temp-file cleanup tool that was linked to the attacker's reverse SSH infrastructure and used to erase intrusion evidence and distribute updated remote-access binaries.

    Activethehackernews.com
  7. Aug 13, 2026

    BleepingComputer reported that the campaign remained active and was installing reverse SSH software for remote access. No new victim count or attacker was named.

    Activebleepingcomputer.com
  8. Aug 12, 2026

    Security reports said exploitation remained active and no attacker had been identified.

    Activescworld.com
  9. Aug 10, 2026

    QUIRSO reported 361 victim IP addresses across 47 countries and evidence of lasting remote access.

    Activemedium.com
  10. Aug 3, 2026

    The first identified compromised systems contacted attacker-controlled domains.

    Activethehackernews.com
  11. Jul 29, 2026

    Broadcom disclosed CVE-2026-59310 and released fixes for affected VMware vCenter versions.

    support.broadcom.com

Sources

Related reports