
Suspected China-Linked Attackers Abuse VMware vCenter Flaw to Deploy Babuk-Style Ransomware
A suspected Chinese threat group is exploiting a VMware vCenter vulnerability to spread a ransomware variant based on the Babuk family. The attack puts virtualized hosting and business systems at risk of sudden encryptio…
A cyberattack campaign attributed to a group with suspected links to China has been targeting VMware vCenter servers, according to a recent security report. VMware vCenter is a central management console that administrators use to control large fleets of virtual servers, which are software-based computers running inside one physical machine. The attackers are said to be exploiting a security weakness in this management tool to gain initial access to a victim's infrastructure. Once inside, they deploy a strain of ransomware based on Babuk, a well-known malware family that has been widely copied since its source code leaked online.
Virtualization has become the backbone of modern web hosting, cloud services, and corporate data centers. A single vCenter instance often has the keys to dozens or hundreds of virtual machines, including those running public websites, customer databases, and backup systems. If an attacker compromises vCenter, they can move laterally across the entire virtualized environment, change administrator passwords, turn off security tools, and encrypt virtual disk files. That makes a vCenter vulnerability especially dangerous for hosting providers and any business that runs VMware ESXi hypervisors and their guest systems.
Babuk is a ransomware family that first appeared in early 2021 and is known for targeting both Windows and Linux systems, including ESXi servers. After the original group's source code was made public, many other criminal and state-linked groups built their own variants, which is likely what 'Babuk-derived' means here. Ransomware of this type locks or encrypts files and then demands payment in cryptocurrency for a decryption key. In a virtualized environment, attackers can encrypt not just individual files but entire virtual disks, bringing websites, email, and internal applications to a standstill in minutes.
The suspected involvement of a China-nexus actor does not change the technical nature of the attack, but it does indicate a higher level of resources and patience. Such groups often spend weeks or months inside a network before deploying ransomware, exfiltrating sensitive data and mapping backup systems first. For organizations that manage VMware infrastructure, the immediate priorities are to verify that vCenter and its underlying ESXi hosts are running the latest available updates, restrict management interfaces so they are not exposed to the open internet, and require strong multi-factor authentication for every administrator account.
Even if you do not run VMware software yourself, the same principles protect websites and online businesses from many similar attacks. Keep every plugin, theme, and content management system up to date, because attackers regularly exploit known weaknesses. Use a password manager to generate long, unique passwords for every login, and enable two-factor authentication wherever it is offered. Make regular backups of your website and store at least one copy offline or in a separate cloud bucket that cannot be reached from your main admin panel. Finally, watch for unexpected file changes, new administrator accounts, or sudden slowdowns, and disconnect affected systems from the network immediately if you suspect an infection.
For businesses that rely on virtualized infrastructure, working with a security-first infrastructure provider such as AEU-I can help keep vCenter and other critical systems patched, monitored, and configured to withstand attacks like this one. Managed security review and continuous monitoring make it far less likely that an intruder can quietly move from a single vulnerability to a full ransomware deployment.
How to Protect Yourself
- Turn on automatic updates for any website control panel or server software you use so security holes get fixed quickly.
- Use a password manager to create a long, unique password for every admin account, and turn on two-factor authentication (a second proof like a code from your phone) wherever possible.
- Make regular backups of your website and files, and keep at least one backup disconnected from your main system so ransomware cannot reach it.
- If you manage a server or virtual machine, restrict admin access to only people who need it and disable remote management when not in use.
- Watch for warning signs like files suddenly renamed or locked, or unexpected system slowdowns, and disconnect the machine from the internet immediately if you suspect an attack.