
China-Nexus APT Exploits Critical VMware vCenter Flaw CVE-2026-59310 to Deploy Babuk-Derived Ransomware
A suspected Chinese state-sponsored actor is actively exploiting a zero-day in VMware vCenter to gain persistent access and deploy sophisticated Babuk-derived ransomware across Western government networks.
Encrygma is selling the entire Full Cyber Weapon Research of China-Nexus APT Exploits Critical VMware vCenter Flaw CVE-2026-59310 to Deploy Babuk-Derived Ransomware for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-59310
- Source:
- Mandiant
- Read Time:
- 4 min
Executive Summary
Over the last 48 hours, intelligence reports from multiple cybersecurity firms have identified a significant escalation in offensive operations by a suspected Chinese nation-state actor. The campaign leverages a critical, newly discovered vulnerability in Broadcom VMware vCenter (CVE-2026-59310) to bypass authentication and achieve remote code execution (RCE). Unlike traditional espionage-only campaigns, this actor is deploying a customized version of the Babuk ransomware, suggesting a strategic shift toward disruptive operations or the use of ransomware as a 'deniable' smokescreen for deeper data exfiltration.
Threat Analysis
The use of ransomware by state-sponsored actors has reached a new peak in August 2026. By utilizing Babuk-derived code—a codebase that has been leaked and modified by various groups—the adversary complicates the attribution process and creates a chaotic environment for incident responders. This 'hybrid' approach allows the actor to disrupt critical operations while maintaining a stealthy foothold in the victim's environment. The targeting of virtualization infrastructure is particularly concerning, as it allows the attacker to compromise multiple guest operating systems simultaneously, maximizing the impact of the intrusion.
Technical Details
CVE-2026-59310 is a heap-overflow vulnerability residing in the vCenter implementation of the Distributed Computing Environment / Remote Procedure Call (DCERPC) protocol. Attackers initiate the exploit by sending a specially crafted network packet to port 135, triggering the overflow and allowing for unauthenticated RCE with administrative privileges.
Once initial access is established, the actor deploys a Linux-based variant of the Babuk ransomware, specifically optimized for ESXi hypervisors. This variant targets virtual disk files (.vmdk), effectively paralyzing the organization's virtualized infrastructure. Furthermore, researchers have observed the use of the 'Cavern' (Cav3rn) command-and-control (C2) framework, which utilizes DNS tunneling and Google Apps Script to blend malicious traffic with legitimate cloud service communications, making detection via traditional firewall logs extremely difficult.
Attribution Assessment
While the deployment of ransomware often points to cybercriminal motives, the infrastructure, victimology, and post-exploitation toolsets align closely with known Chinese Advanced Persistent Threat (APT) clusters. Specifically, the tactics, techniques, and procedures (TTPs) mirror those of 'Salt Typhoon' and 'APT41' (Wicked Panda). The focus on high-value government ministries and defense industrial base (DIB) entities in North America and Europe further supports the assessment that this is a state-directed operation aimed at both intelligence gathering and potential pre-positioning for future conflict.
Implications
The exploitation of virtualization management software like vCenter acts as a 'force multiplier' for state actors. By gaining control over the management layer, the adversary bypasses individual server security controls and gains a 'god-view' of the network. This level of access is difficult to remediate without a complete rebuild of the virtual environment, leading to prolonged downtime for essential government services.
Recommendations
Encrygma recommends that all organizations running VMware vCenter immediately apply the security patches for CVE-2026-59310. Additionally, security teams should:
- Implement strict network segmentation to ensure that vCenter management interfaces are not accessible from the public internet or general employee subnets.
- Monitor for unusual DNS queries to non-standard domains and traffic spikes associated with Google Apps Script URLs.
- Conduct a thorough audit of all service accounts associated with the virtualization layer, looking for unauthorized credential creation or 'pass-the-cookie' activity.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

China-Linked JDY Botnet Escalates Reconnaissance Against U.S. Military Infrastructure

State-Sponsored Actors Pivot to Ransomware-as-a-Cover for Global Espionage Campaigns

