Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
A Chinese-nexus advanced persistent threat (APT) group, suspected to be operating from China, exploited a newly patched VMware vCenter vulnerability (CVE-2026-59310) to deploy Babuk-derived ransomware. The attack involved a multi-stage process of exploiting multiple vulnerabilities, creating administrative accounts, and leveraging cron jobs to establish persistence and execute malicious code. Researchers attributed the campaign to a group likely operating in the UTC+08:00 time zone, and noted that while ransomware deployment was observed, it may not have been the primary objective of the campaign, potentially serving as a smokescreen to evade detection.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
