This ransomware gang is using SSH tunnels to aim VMware appliances




  • Researchers find computer pirates who use the SSH VMware ESXI SSH in attacks
  • Campaigns end ransomware infections
  • The researchers suggested ways to search for compromise indicators.

Cybercriminals are using SSH tunnel functionality in Esxi Bare metal hypervisors for stealthy persistence, to help them implement ransomware at the target final points, experts warned.

Sygnia cyber security researchers have highlighted how ransomware actors are aimed at virtualized infrastructure, particularly vmware esxi appliances, business grade hypervisors and basic metals used to virtualize hardware, allowing multiple virtual machines to execute on a unique physical server.

Leave a Comment

Your email address will not be published. Required fields are marked *