Agenda Ransomware Targets ESXi Hosts


Userlevel 7
Badge +17

Hey Community -

Sorry to be the bearer of unpleasant security news as of late, but better to be proactive rather than reactive, as they say, right? 🤷🏻‍♂️

It appears the Agenda Ransomware group, which was first detected in 2022, has been ramping up infiltrations recently. It’s ransomware, Agenda (aka Qilin and Water Galura), infected the likes of healthcare, manufacturing, and educational entities 2years ago, but have since rewrote their ransomware to now target OS’s, and specifically geared towards the VMware hypervisor.

This new variant was detected by TrendMicro , which they say “comes with a variety of new functionalities and stealth mechanisms, & sets its sights squarely on VMware vCenter and ESXi servers.

You can read more about this ransomware variant in the article below, as well as the TM link above:

https://www.darkreading.com/cloud-security/agenda-ransomware-vmware-esxi-servers

I’m not aware of any messaging by VMware as of yet about a potential patch/fix for this threat. If anyone else knows of a VMware KB/CVE, please share in the comments below.


5 comments

Userlevel 7
Badge +2

@coolsport00 ,
Some of the preventative measure I can think of:

  1. Do not allow vCenter Web Console access over the internet.
  2. Do not use NFS as the VM datastore.

Hopefully others can also help sharing the preventative measure.

Userlevel 7
Badge +4

I’m so happy that I’m not a sysadmin anymore during this ransomware era.
It’s hard to be protected nowadays. :(

Userlevel 7
Badge +20

Wonderful more VMware exploits to patch.

Userlevel 7
Badge +17

Wonderful more VMware exploits to patch.

Right? 🙄

Userlevel 7
Badge +6

@coolsport00 ,
Some of the preventative measure I can think of:

  1. Do not allow vCenter Web Console access over the internet.
  2. Do not use NFS as the VM datastore.

Hopefully others can also help sharing the preventative measure.

And if you’re using ISCSI, make sure it’s locked down to specific initiators or using CHAP authentication.  Allowing any is a bad idea….

Comment