
A suspected China-nexus advanced persistent threat (APT) is actively exploiting CVE-2026-59310, a CVSS 9.8-rated directory traversal vulnerability in VMware vCenter, just five days after its public disclosure. German incident response firm QUIRSO assessed with moderate confidence that a Chinese-speaking threat actor — operating in the UTC+08:00 time zone and leaving Chinese-language artifacts in attacker scripts — is behind the campaign. As of its latest analysis, the activity has compromised an estimated 361 unique victim IP addresses in 47 countries, with the heaviest concentrations in Germany (55), the United States (41), Turkey (38), Iran (26), and France (25).
Once inside a vCenter server, the attackers deploy a backdoor called “linuxFile” (also known as “systemlog”) that communicates over an obfuscated WebSocket channel and maintains persistence through systemd and cron jobs. The same infrastructure also pushes reverse SSH binaries and additional malware payloads. QUIRSO found evidence of Babuk-derived ransomware being deployed on ESXi hosts, encrypting files with the “.babyk” extension — but researchers believe this ransomware may serve as a deliberate smokescreen rather than the campaign’s primary goal, since encrypting ESXi log files conveniently destroys the telemetry attackers would prefer investigators not see. The attackers also exploited CVE-2026-59309, a related authentication bypass flaw, to create hidden administrative accounts on compromised vCenter instances.
How to check if you’re affected
Affected versions of VMware vCenter Server are any builds older than the patches Broadcom released on July 29, 2026, specifically targeting CVE-2026-59310 and CVE-2026-59309. If your organization runs VMware vCenter, check Broadcom’s security advisory for CVE-2026-59310 to verify your installed version. Look for unauthorized administrator accounts in vCenter (the attackers used names like “vcenter_admin”), review /etc/cron.d/ for unexpected cron entries, and check for unknown processes connecting to external IP addresses on non-standard ports. Indicators of compromise from QUIRSO include connections to intel.se9ly9upbhay.shop and staging downloads from 5.34.177[.]38, 185.144.28[.]120, and 5.34.176[.]100.
Sources
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware — The Hacker News
- QUIRSO incident response research: “Global Exploitation of CVE-2026-59310 by Suspected Chinese-Nexus APT” (published on Medium)
