Tech

This ransomware gang is using SSH tunnels to target VMware appliances

Share
Share


  • Researchers find hackers using VMware ESXi’s SSH tunneling in attacks
  • The campaigns end up with ransomware infections
  • The researchers suggested ways to hunt for indicators of compromise

Cybercriminals are using SSH tunneling functionality on ESXi bare metal hypervisors for stealthy persistence, to help them deploy ransomware on target endpoints, experts have warned.

Cybersecurity researchers from Sygnia have highlighted how ransomware actors are targeting virtualized infrastructure, particularly VMware ESXi appliances, enterprise-grade, bare-metal hypervisors used to virtualize hardware, enabling multiple virtual machines to run on a single physical server.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Microsoft working on next-gen Xbox video game console
Tech

Microsoft working on next-gen Xbox video game console

Credit: CC0 Public Domain Xbox president Sarah Bond on Tuesday confirmed that...

Trump extends TikTok deadline for third time
Tech

Trump extends TikTok deadline for third time

Any deal to sell TikTok’s business in the United States would need...

New rules may not change dirty and deadly ship recycling business
Tech

New rules may not change dirty and deadly ship recycling business

This aerial photograph taken on February 18, 2025 shows a general view...