
RansomHub and Akira Exploit Critical VMware ESXi Flaw in Global Double-Extortion Campaign
Ransomware groups are actively exploiting a high-severity VMware ESXi vulnerability to gain full administrative access, leading to widespread data exfiltration and server encryption.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2024-37085
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
Intelligence reports from late July 2026 confirm a coordinated surge in ransomware attacks targeting virtualized environments. Major Ransomware-as-a-Service (RaaS) affiliates, specifically those associated with RansomHub and Akira, have been observed exploiting a critical authentication bypass vulnerability in VMware ESXi (tracked as CVE-2024-37085). This campaign marks a significant shift in threat actor focus toward hypervisor-level persistence, allowing for the simultaneous encryption of multiple virtual machines (VMs) and the facilitation of double-extortion tactics. The Administration for Cyber Security (ACS) and Microsoft MSTIC have issued urgent advisories following successful breaches at several Fortune 500 manufacturing firms and regional financial institutions over the last 48 hours.
Threat Analysis
The current threat landscape is characterized by a "hypervisor-first" strategy. By compromising the ESXi host, attackers bypass guest-level security controls and EDR solutions. Once administrative access is achieved, the actors utilize custom tooling to exfiltrate massive volumes of sensitive data before deploying the final ransomware payload. This double-extortion model—threatening public data disclosure alongside service disruption—has proven highly effective, with RansomHub alone claiming 45 new victims in the current reporting cycle. The integration of generative AI tools has further streamlined the initial access phase, with attackers using AI-generated spear-phishing emails that mimic internal IT communications with nearly perfect accuracy.
Technical Details
The primary attack vector involves the exploitation of CVE-2024-37085, a flaw in the way ESXi handles Active Directory (AD) group authentication. Attackers with low-privileged AD access can create or rename a group to "ESXi Admins," which the hypervisor automatically grants full administrative rights.
Following the privilege escalation, threat actors deploy specialized Linux-based lockers. Technical analysis of the Akira variant used in these attacks reveals the use of the ChaCha20 stream cipher for speed, coupled with RSA-4096 for key encapsulation. For exfiltration, the groups are leveraging Rclone and WinSCP to move data to Mega.nz and S3 buckets. In several instances, the attackers used the "Bring Your Own Vulnerable Driver" (BYOVD) technique to disable EDR agents on the host before commencing encryption.
Attribution Assessment
Encrygma analysts attribute this activity with high confidence to RansomHub and Akira (likely descendants of the Conti and ALPHV ecosystems). RansomHub, which emerged as a dominant force in early 2024, continues to attract high-tier affiliates due to its 90% profit-sharing model. Akira's involvement is signaled by its distinct C++ codebase and specific victim-naming conventions on its Tor-based leak site. While these groups operate under a RaaS model, the high degree of technical overlap suggests a shared resource pool or common initial access brokers (IABs) focusing on enterprise AD environments.
Implications
The exploitation of hypervisors poses a systemic risk to business continuity. Because ESXi hosts often manage critical infrastructure, database servers, and ERP systems, the recovery time objective (RTO) for affected organizations has increased from days to weeks. Furthermore, the focus on data exfiltration over simple encryption increases the long-term regulatory and reputational risk, as GDPR and CCPA violations become inevitable following the leak of PII and proprietary trade secrets. The surge in these attacks indicates that traditional perimeter defenses are insufficient against contemporary privilege escalation techniques.
Recommendations
- Immediate Patching: Prioritize the application of security updates for all VMware ESXi hosts to remediate CVE-2024-37085.
- AD Hardening: Audit Active Directory for the existence of "ESXi Admins" groups and implement strict GPO controls to prevent unauthorized group creation.
- Micro-segmentation: Implement Zero Trust network architecture to isolate hypervisor management interfaces from general user segments.
- Immutable Backups: Ensure that off-site, immutable backups are tested and verified for rapid restoration of virtualized environments.
- Multi-Factor Authentication (MFA): Enforce phishing-resistant MFA (e.g., FIDO2) for all administrative accounts and VPN access points.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Qilin Ransomware Gang Steps Up Dual-Extortion Onslaught Across Government and Supply Chain Entities

GOLD SHERWOOD Deploys Rapid Sub-24-Hour Ransomware Playbook Against Enterprise Targets

