News Room
16
Share
China-Nexus APT Exploits Critical VMware vCenter Flaw CVE-2026-59310 to Deploy Babuk-Derived Ransomware
criticalState Cyber Warfare

China-Nexus APT Exploits Critical VMware vCenter Flaw CVE-2026-59310 to Deploy Babuk-Derived Ransomware

A suspected Chinese state-sponsored actor is actively exploiting a zero-day in VMware vCenter to gain persistent access and deploy sophisticated Babuk-derived ransomware across Western government networks.

₿

Encrygma is selling the entire Full Cyber Weapon Research of China-Nexus APT Exploits Critical VMware vCenter Flaw CVE-2026-59310 to Deploy Babuk-Derived Ransomware for ₿ 0.10 BTC. Contact us.

20 August 2026Last updated 20 August 20264 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-59310
Source:
Mandiant
Read Time:
4 min

Executive Summary

Over the last 48 hours, intelligence reports from multiple cybersecurity firms have identified a significant escalation in offensive operations by a suspected Chinese nation-state actor. The campaign leverages a critical, newly discovered vulnerability in Broadcom VMware vCenter (CVE-2026-59310) to bypass authentication and achieve remote code execution (RCE). Unlike traditional espionage-only campaigns, this actor is deploying a customized version of the Babuk ransomware, suggesting a strategic shift toward disruptive operations or the use of ransomware as a 'deniable' smokescreen for deeper data exfiltration.

Threat Analysis

The use of ransomware by state-sponsored actors has reached a new peak in August 2026. By utilizing Babuk-derived code—a codebase that has been leaked and modified by various groups—the adversary complicates the attribution process and creates a chaotic environment for incident responders. This 'hybrid' approach allows the actor to disrupt critical operations while maintaining a stealthy foothold in the victim's environment. The targeting of virtualization infrastructure is particularly concerning, as it allows the attacker to compromise multiple guest operating systems simultaneously, maximizing the impact of the intrusion.

Technical Details

CVE-2026-59310 is a heap-overflow vulnerability residing in the vCenter implementation of the Distributed Computing Environment / Remote Procedure Call (DCERPC) protocol. Attackers initiate the exploit by sending a specially crafted network packet to port 135, triggering the overflow and allowing for unauthenticated RCE with administrative privileges.

Once initial access is established, the actor deploys a Linux-based variant of the Babuk ransomware, specifically optimized for ESXi hypervisors. This variant targets virtual disk files (.vmdk), effectively paralyzing the organization's virtualized infrastructure. Furthermore, researchers have observed the use of the 'Cavern' (Cav3rn) command-and-control (C2) framework, which utilizes DNS tunneling and Google Apps Script to blend malicious traffic with legitimate cloud service communications, making detection via traditional firewall logs extremely difficult.

Attribution Assessment

While the deployment of ransomware often points to cybercriminal motives, the infrastructure, victimology, and post-exploitation toolsets align closely with known Chinese Advanced Persistent Threat (APT) clusters. Specifically, the tactics, techniques, and procedures (TTPs) mirror those of 'Salt Typhoon' and 'APT41' (Wicked Panda). The focus on high-value government ministries and defense industrial base (DIB) entities in North America and Europe further supports the assessment that this is a state-directed operation aimed at both intelligence gathering and potential pre-positioning for future conflict.

Implications

The exploitation of virtualization management software like vCenter acts as a 'force multiplier' for state actors. By gaining control over the management layer, the adversary bypasses individual server security controls and gains a 'god-view' of the network. This level of access is difficult to remediate without a complete rebuild of the virtual environment, leading to prolonged downtime for essential government services.

Recommendations

Encrygma recommends that all organizations running VMware vCenter immediately apply the security patches for CVE-2026-59310. Additionally, security teams should:

  1. Implement strict network segmentation to ensure that vCenter management interfaces are not accessible from the public internet or general employee subnets.
  2. Monitor for unusual DNS queries to non-standard domains and traffic spikes associated with Google Apps Script URLs.
  3. Conduct a thorough audit of all service accounts associated with the virtualization layer, looking for unauthorized credential creation or 'pass-the-cookie' activity.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo