Saturday, March 25, 2023
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory
  • Login
  • Register
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7 News
No Result
View All Result

Home > Cybersecurity > New variant of VMware ransomware prevents recovery

New variant of VMware ransomware prevents recovery

The VMware ESXi exploit now has a new variant that renders the recovery tools useless by scanning and encrypting larger amounts of data.


Ezgi Koc Ezgi Koc
February 9, 2023
2 min read
New variant of VMware ransomware prevents recovery
  • On February 6th, 2023, we published an article detailing how malicious actors launched new attacks using two-year-old VMware vulnerabilities known as CVE-2021-21972.
  • CISA (Cybersecurity and Infrastructure Security Agency) released a ransomware recovery tool for everyone impacted by the VMware ESXi exploits a few days later.
  • Now, it appears that a new wave of attacks is using a new ransomware variant that has been modified to scan and encrypt files of higher sizes.

We reported on February 6th, 2023, how hostile actors used two-year-old VMware vulnerabilities, identified as CVE-2021-21972, to launch fresh attacks. The vulnerability has a CVSSv3 base score of 9.8, a remote code execution vulnerability. A couple of days later, CISA (Cybersecurity and Infrastructure Security Agency) published a ransomware recovery tool for everyone affected by the VMware ESXi exploit. Now, there seems to be a new wave of attacks using a new variant.

The newer version prevents recovery

The way the ransomware used to work is that it only encrypted files in small bits and left quite large gaps of unencrypted files. Now, with the new variant, the malicious actors seem to have changed the ransomware to scan and encrypt files of larger sizes. This renders the recovery tools useless as data will be even more encrypted. Since a larger percentage of the total data will be encrypted, recovery tools for the first variant will not be able to help the second variant, which makes the ransomware even more dangerous.

Impacted Products

  • VMware ESXi.
  • VMware vCenter Server (vCenter Server).
  • VMware Cloud Foundation (Cloud Foundation).

As usual, since the “ESXiArgs” ransomware targets long-unpatched and unprotected instances of VMware ESXi, restricting IP access to trusted sources only and updating to the latest version of ESXi is a good way to help protect yourself from potential threats.

See more Cybersecurity News

A comprehensive guide to understanding Cybersecurity: What is Cybersecurity?


Tags: RansomwareVMware
Ezgi Koc

Ezgi Koc

Ezgi Koc is an editor at Cloud7. She graduated from Ege University with a bachelor's degree in English Language and Literature. She has always had great interest in technology, both hardware and software, since her childhood and decided to pursue a career that would enable her to broaden her horizons in this field. She is very passionate about video games as a Twitch affiliate and streams games in her free time.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Next Post
Microsoft's new AI-powered Bing search engine and Edge browser

Microsoft's new AI-powered Bing search engine and Edge browser

Related News

7 best practices and tools to use for Linux security

7 best practices and tools to use for Linux security

March 24, 2023 5:00 pm
CISA aims to identify vulnerabilities that attract ransomware

CISA aims to identify vulnerabilities that attract ransomware

March 22, 2023 2:10 pm
7 best cybersecurity schools

7 best cybersecurity schools

March 21, 2023 9:00 pm
Akamai researchers warn about the new HinataBot botnet

Akamai researchers warn about the new HinataBot botnet

March 20, 2023 6:10 pm
Get free daily newsletters from Cloud7 News Get the Cloud7 Newsletter
Select list(s):

Check your inbox or spam folder to confirm your subscription.

By subscribing, you agree to our
Copyright Policy and Privacy Policy

Get the free newsletter

Subscribe to receive the latest IT business updates straight to your inbox.

Select list(s):

Check your inbox or spam folder to confirm your subscription.

Recent News

  • Podman Desktop – Containers & Kubernetes (Podcast #15 w/ Markus Eisele)
  • What is a Daemon in Linux?
  • 7 best practices and tools to use for Linux security
  • Photopea review: The best free Photoshop alternative for Linux
  • CloudFest 2023 is completed

Cloud7 News
Cloud7 is a news source that publishes the latest news, reviews, comparisons, opinions, and exclusive interviews to help tech users of high-experience levels in the IT industry.

EXPLORE

  • Web Hosting
  • Cloud Computing
  • Data Center
  • Cybersecurity
  • Linux
  • Network/Internet
  • Software
  • Hardware
  • Artificial Intelligence
  • How-Tos
  • Troubleshooting

RESOURCES

  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

Get the Cloud7 Newsletter

Get FREE daily newsletters from Cloud7 delivering the latest news and reviews.

  • About Us
  • Privacy & Policy
  • Copyright Policy
  • Contact

© 2023, Cloud7 News. All rights reserved.

No Result
View All Result
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

© 2023, Cloud7 News. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.