IC Technology & Cyber — 2026-08-19

China-Nexus APT Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware

BLUFReverse_ssh persistence surviving patching means every internet-facing vCenter instance exposed before remediation requires a full forensic sweep, not just a version upgrade, to confirm attacker eviction.

A suspected China-nexus APT actor exploited CVE-2026-59310, a critical directory-traversal flaw in VMware's vCenter Syslog server rated CVSS 9.8, beginning August 3, five days after Broadcom's July 29 advisory 12. German incident-response firm QUIRSO reported the campaign reached 361 victim IP addresses across 47 countries, with Germany, the United States, Turkey, Iran and France accounting for 185 of them, and said no victims were identified in mainland China 1. QUIRSO's investigation of one compromised vCenter appliance traced the intrusion from likely unauthenticated remote code execution through cron-based persistence, SSO account creation, ESXi access and deployment of Babuk-derived ransomware, and separately flagged possible parallel exploitation of a related authentication-bypass flaw, CVE-2026-59309, on August 1 13. QUIRSO assessed with moderate confidence that the actor is Chinese-speaking based on activity clustering in the UTC+08:00 time zone, and suspects the ransomware deployment functioned as a smokescreen to destroy ESXi log telemetry and distract defenders rather than serving as the campaign's primary objective 1. The actor established persistence via the open-source reverse_ssh framework, which QUIRSO and Dark Reading noted can preserve attacker access even after affected systems are patched 24.

Analysis
Persistence via reverse_ssh turns vCenter patching into a race defenders lose, since outbound reverse-shell channels survive version upgrades and demand a separate forensic sweep to sever attacker access. The absence of victims in mainland China alongside concentration in Germany, the United States, Turkey, Iran and France points to indiscriminate scanning of internet-facing appliances rather than sector-targeted espionage, meaning every exposed instance now warrants compromise assumption regardless of patch state. QUIRSO's continued observation of new victims connecting to attacker infrastructure indicates the campaign remains active weeks after initial disclosure, though reporting traces to a single incident-response investigation, with other outlets amplifying rather than independently verifying victim counts or attribution. The August 1 authentication-bypass activity, tied to a distinct IP and custom user agents, may instead reflect a separate actor operating in parallel rather than one coordinated Chinese-nexus campaign.
4 sources
  1. Global Exploitation of CVE-2026-59310 by Suspected Chinese-Nexus APT & Related CVE-2026-59309 Activity - QUIRSO GmbH
  2. Global Threat Campaign Hits Critical VMware vCenter Flaw - Dark Reading
  3. Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware - The Hacker News
  4. vCenter Flaw Exploited Just Five Days After Disclosure - Infosecurity Magazine

View in full brief →

UNCLASSIFIED // OPEN SOURCE