News Room
16
Share
RansomHub and Akira Exploit Critical VMware ESXi Flaw in Global Double-Extortion Campaign
criticalThreat Intelligence

RansomHub and Akira Exploit Critical VMware ESXi Flaw in Global Double-Extortion Campaign

Ransomware groups are actively exploiting a high-severity VMware ESXi vulnerability to gain full administrative access, leading to widespread data exfiltration and server encryption.

28 July 2026Last updated 20 August 20265 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2024-37085
Source:
Microsoft MSTIC
Read Time:
5 min

Executive Summary

Intelligence reports from late July 2026 confirm a coordinated surge in ransomware attacks targeting virtualized environments. Major Ransomware-as-a-Service (RaaS) affiliates, specifically those associated with RansomHub and Akira, have been observed exploiting a critical authentication bypass vulnerability in VMware ESXi (tracked as CVE-2024-37085). This campaign marks a significant shift in threat actor focus toward hypervisor-level persistence, allowing for the simultaneous encryption of multiple virtual machines (VMs) and the facilitation of double-extortion tactics. The Administration for Cyber Security (ACS) and Microsoft MSTIC have issued urgent advisories following successful breaches at several Fortune 500 manufacturing firms and regional financial institutions over the last 48 hours.

Threat Analysis

The current threat landscape is characterized by a "hypervisor-first" strategy. By compromising the ESXi host, attackers bypass guest-level security controls and EDR solutions. Once administrative access is achieved, the actors utilize custom tooling to exfiltrate massive volumes of sensitive data before deploying the final ransomware payload. This double-extortion model—threatening public data disclosure alongside service disruption—has proven highly effective, with RansomHub alone claiming 45 new victims in the current reporting cycle. The integration of generative AI tools has further streamlined the initial access phase, with attackers using AI-generated spear-phishing emails that mimic internal IT communications with nearly perfect accuracy.

Technical Details

The primary attack vector involves the exploitation of CVE-2024-37085, a flaw in the way ESXi handles Active Directory (AD) group authentication. Attackers with low-privileged AD access can create or rename a group to "ESXi Admins," which the hypervisor automatically grants full administrative rights.

Following the privilege escalation, threat actors deploy specialized Linux-based lockers. Technical analysis of the Akira variant used in these attacks reveals the use of the ChaCha20 stream cipher for speed, coupled with RSA-4096 for key encapsulation. For exfiltration, the groups are leveraging Rclone and WinSCP to move data to Mega.nz and S3 buckets. In several instances, the attackers used the "Bring Your Own Vulnerable Driver" (BYOVD) technique to disable EDR agents on the host before commencing encryption.

Attribution Assessment

Encrygma analysts attribute this activity with high confidence to RansomHub and Akira (likely descendants of the Conti and ALPHV ecosystems). RansomHub, which emerged as a dominant force in early 2024, continues to attract high-tier affiliates due to its 90% profit-sharing model. Akira's involvement is signaled by its distinct C++ codebase and specific victim-naming conventions on its Tor-based leak site. While these groups operate under a RaaS model, the high degree of technical overlap suggests a shared resource pool or common initial access brokers (IABs) focusing on enterprise AD environments.

Implications

The exploitation of hypervisors poses a systemic risk to business continuity. Because ESXi hosts often manage critical infrastructure, database servers, and ERP systems, the recovery time objective (RTO) for affected organizations has increased from days to weeks. Furthermore, the focus on data exfiltration over simple encryption increases the long-term regulatory and reputational risk, as GDPR and CCPA violations become inevitable following the leak of PII and proprietary trade secrets. The surge in these attacks indicates that traditional perimeter defenses are insufficient against contemporary privilege escalation techniques.

Recommendations

  1. Immediate Patching: Prioritize the application of security updates for all VMware ESXi hosts to remediate CVE-2024-37085.
  2. AD Hardening: Audit Active Directory for the existence of "ESXi Admins" groups and implement strict GPO controls to prevent unauthorized group creation.
  3. Micro-segmentation: Implement Zero Trust network architecture to isolate hypervisor management interfaces from general user segments.
  4. Immutable Backups: Ensure that off-site, immutable backups are tested and verified for rapid restoration of virtualized environments.
  5. Multi-Factor Authentication (MFA): Enforce phishing-resistant MFA (e.g., FIDO2) for all administrative accounts and VPN access points.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo