Skip to main content
Question

Recent cyber attacks against VMware ESXi

  • October 9, 2026
  • 0 comments
  • 11 views

ClimbUp
Forum|alt.badge.img

There are so many data-breach incidents reported by news media day after day in Japan. Ransomware incidents seem to be increasing as well, although we do not hear about them as often as data-breach incidents. Maybe they have become so common and no longer considered newsworthy.

Having said that, there was a new incident just reported on October 7th and it appears to be a special case. The first report was about Ibaraki Prefecture municipal office and municipal police websites closure due to IDCF Cloud service outage. The IDCF Cloud is run by Softbank subsidiary IDC Frontier, which then announced that a part of their system was compromised. Later, more details were announced that IDCF Cloud’s East Japan Region 1 was down due to a ransomware attack, which impacted 495 organizations throughout Japan.

According to public information on the IDC Frontier website, IDCF Cloud service’s East Japan Region 1 uses VMware ESXi / vCenter, suggesting the ransomware targeted that specific deployment, though it has not been officially confirmed yet.

No matter whether VMware ESXi / vCenter were actually attacked or not, generally speaking, it is true that the use of virtual machines inevitably depends on the hypervisor security. If the hypervisor is compromised, all the VMs hosted by the hypervisor are at risk too.

Therefore, in this blog article today, I would like to review how we can strengthen hypervisor security through our routine best practices.

Attack vectors

To start, let’s narrow down how attackers can gain access to a hypervisor. Main attack vectors could be narrowed down to the following four patterns.

  1. Administrator access: There are many possibilities, e.g. admin credentials could be stolen, admin terminals could be hacked, or admins themselves could be malicious actors (insider threat). The most common is that admins fall victim to phishing. Needless to say, we should all be careful about external links, attachments and downloading anything untrusted. At the same time, enforcing the least privilege principle is very important.
  2. vCenter / ESXi vulnerabilities: If malicious actors somehow get to the admin interface, they can exploit the vulnerabilities. To prevent that, the system has to be kept up to date always and the admin interface should never be exposed to the internet.
  3. Lateral movement via Active Directory: When ESXi is integrated with Active Directory (AD), AD can be a prime target. Admin access within AD must be secured, as outlined in point 1.
  4. Intrusion from VM to host: It is possible to exploit the hypervisor vulnerabilities from a guest VM. Therefore, VM accesses must also be tightened and monitored. A proper segmentation should be applied as well.    

Actual incident examples

We can learn from actual incidents in the recent years.

According to Microsoft, malicious actors such as Storm-0506 and Octo Tempest have exploited CVE-2024-37085, where ESXi hosts integrated with Active Directory automatically grant full admin privileges to any domain group named "ESX Admins". That means anybody who gets access to Active Directory can easily get into the ESXi host as well.

Last year, UK retailer Marks & Spencer was attacked by DragonForce and Scattered Spider who reportedly used ESXi-focused payloads and credential abuse.

VMware reported five critical vulnerabilities in its core virtualization products in 2024 and four in 2025. Some of them were remotely exploitable or allowed an attacker to escape a compromised guest VM and execute code on the hypervisor.

Even this year, Broadcom's July patch included two vCenter vulnerabilities, an authentication bypass and a path traversal bug allowing arbitrary code execution, plus an ESXi VM-escape vulnerability in the VMXNET3 adapter.   

Most of the attack vectors mentioned above rely on security gaps that could easily be prevented through routine best practices. Even the IDC Frontier incident may have stemmed from a simple oversight, despite media outlets and social networks hyping up unstoppable AI threats. It is undeniable that the attacker actually used AI to identify vulnerabilities, but nothing has been confirmed yet in this case. Media coverage appears overly focused on AI risks, stoking unnecessary panic rather than promoting foundational security hygiene.

Best practices

Before worrying too much about emerging AI threats, we should go back to basics to strengthen the hypervisor security first. Here are some basic best practices.

1. Do not forget about the hypervisor while managing your VMs.

Organizations often secure guest VMs diligently while overlooking the underlying host. As well as VMs, hypervisors must be patched regularly, and any critical security patches must be implemented immediately.  

2. Do not expose the management interface to the internet.

It has to be isolated and its access has to be restricted to special personnel with least privilege principle enforced.

3. Limit Active Directory account access.

Limit which groups / users are granted admin rights and integrate with Active Directory only when necessary. Use local non-domain accounts for management, and limit which domain accounts can reach the hypervisor.

4. Minimize the attack surface.

Do not leave the SSH connection open after you finish using it. Unnecessary ports should be closed too.

5. Back up.

Follow the 3-2-1 back up rule. It must be tested regularly so the recovery works without fail. And, one copy of the backup file must be off-line, air-gapped and immutable. That means, enhancing the traditional 3-2-1 strategy, the 3-2-1-1-0 back up strategy that Veeam recommends must be practiced.