This ransomware gang uses SSH tunnels to target VMware devices


  • Researchers find hackers using VMware ESXi SSH tunneling in attacks
  • The campaigns are ended up with ransomware infections
  • Researchers have suggested means to search for compromise indicators

Cybercriminals use SSH tunneling features on ESXi Bare Metal hypervisors for furtive persistence, to help them deploy ransomware on target termination points, experts warned.

Sygnia cybersecurity researchers highlighted how ransomware players target virtualized infrastructure, in particular ESXi vmware devices, quality naked metal hypervisors in business used to virtualize equipment, allowing several virtual machines to execute one Physical server.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top