Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

A China-Nexus Actor Exploits VMware vCenter Flaw, Deploying Babuk-Derived Ransomware

Cybersecurity researchers have uncovered a sophisticated cyberattack that leverages a previously unknown vulnerability in VMware’s vCenter management software to deploy a custom-built ransomware variant derived from the infamous Babuk strain. The attack is suspected to be linked to China-based threat actors, who have been known for their aggressive and targeted operations.

The attackers appear to have exploited an unpatched flaw in vCenter, allowing them to gain unauthorized access to affected networks. Once inside, they used a custom-built tool to map the network’s internal topology and identify sensitive assets. The researchers observed that the attackers then deployed a bespoke ransomware payload, which was created by modifying the Babuk malware framework.

The use of VMware vCenter is widespread across various industries, including finance, healthcare, and education. Given its critical role in managing virtualized environments, an unpatched vulnerability in the software poses significant risks to organizations that rely on it. The attackers’ ability to exploit this flaw and deploy custom-built malware underscores the importance of maintaining up-to-date security patches and monitoring network activity for signs of suspicious behavior.

The researchers noted that the attackers’ primary goal was likely data exfiltration rather than encryption, as they did not appear to prioritize ransomware payments. This observation suggests that the attackers may be more interested in stealing sensitive information or disrupting operations than in generating revenue through extortion. The use of a custom-built tool to map the network’s internal topology also implies that the attackers are highly sophisticated and well-resourced.

The incident serves as a stark reminder of the importance of implementing robust security measures, including patch management, network monitoring, and user education. Organizations that rely on VMware vCenter should prioritize updating their software and implementing additional security controls to mitigate potential risks. Furthermore, users should remain vigilant for signs of suspicious activity, such as unusual login attempts or anomalies in network traffic.

To minimize the risk of falling victim to similar attacks, we recommend that organizations take a proactive approach to security by:

* Regularly updating VMware vCenter and other critical software with the latest security patches

* Implementing robust network monitoring tools to detect and respond to potential threats

* Educating users on safe practices for managing virtualized environments and handling sensitive data

By prioritizing security and staying informed about emerging threats, organizations can better protect themselves against increasingly sophisticated cyberattacks.


Source: The Hacker News — 2026-08-17