
VMware vCenter Exploit Campaign Enables Covert, Long-Lasting Access for Attackers
Security teams report that threat actors are actively breaking into VMware vCenter servers through an unpatched vulnerability, then setting up hidden backdoors to maintain remote control for months.
VMware vCenter is a central management platform used by IT teams and hosting providers to control large groups of virtual machines, which are isolated software environments that run websites, databases, and applications. According to a security news report, attackers are actively exploiting a vulnerability in VMware vCenter to gain persistent remote access. In plain terms, persistent remote access means that once an attacker breaks in, they install hidden methods to keep returning to the system even after it restarts or after passwords are changed. This is not a quick smash-and-grab attack. It is a stealthy, long-term takeover of the very tool that governs an organisation's core server infrastructure.
When attackers exploit the vCenter flaw, they typically obtain high-level privileges that let them run commands directly on the server. From there, they create new administrator accounts that look legitimate, schedule automatic tasks to re-establish their access, or inject malicious code into normal processes. These techniques are difficult to spot because they blend in with ordinary administrative activity. The goal is persistence. By keeping a hidden foothold inside vCenter for weeks or months, the attackers can silently collect data, tamper with virtual machines, or deploy ransomware at a time of their choosing.
The impact on website owners and hosting businesses is significant. Many web hosts and cloud providers use VMware vCenter to manage the virtual servers that host customer websites. If attackers control vCenter, they can often reach every virtual machine managed by that system. This means they could read or change website files, steal customer databases, or shut down services entirely. Even if individual websites are isolated in separate virtual machines, a compromised management layer can be used to break that isolation and move from one customer environment to another. For any business that relies on a hosting provider or runs its own VMware infrastructure, this attack path is a serious threat.
To reduce risk, organisations should treat vCenter as a critical asset and apply security patches from VMware as soon as they are released. Network access to the vCenter management interface should be restricted so that it is not reachable from the public internet. Multi-factor authentication, which requires a second proof of identity beyond a password, should be enforced for every administrator account. IT teams should review all admin accounts and scheduled tasks for anything unusual, and monitor logs for signs of persistence such as new accounts created outside normal change windows. Virtualisation management tools must be separated from general network traffic and treated with the same seriousness as the servers they control.
For organisations that manage VMware environments but lack dedicated security expertise, a security-first IT team such as AEU-I can assist with auditing vCenter access controls, reviewing patch schedules, and monitoring logs to detect persistent backdoors before they lead to a full compromise. Website owners who do not manage vCenter directly should still ask their hosting provider whether their virtualisation management tools are up to date and properly secured. The ability of attackers to maintain long-term remote access inside a management platform is a reminder that trust in infrastructure must be earned through continuous verification and timely updates.
How to Protect Yourself
- Ask your hosting provider whether they use VMware vCenter and confirm that the latest security patches have been applied.
- Turn on two-factor authentication for your hosting account and any admin panel you can access, so a stolen password alone is not enough for an attacker.
- Regularly back up your website and database, and store the backups in a separate location so you can restore if your site is altered.
- Review the list of administrator users on your hosting control panel and remove any accounts you do not recognise.
- If you notice unexpected changes to your website files, slow performance, or unknown scheduled tasks, contact your hosting provider immediately and change your passwords.