AIO APEX

China-nexus hackers exploit critical VMware vCenter flaw to breach 361 organizations across 47 countries

The Hacker News / QUIRSO
Share:
China-nexus hackers exploit critical VMware vCenter flaw to breach 361 organizations across 47 countries

A suspected China-nexus advanced persistent threat group has exploited a critical directory-traversal vulnerability in Broadcom VMware vCenter to compromise 361 unique victim IP addresses across 47 countries, according to German incident response firm QUIRSO. The exploitation campaign began just five calendar days after Broadcom publicly disclosed and patched the flaw on July 29, 2026 — a narrow window that underscores how quickly attackers now weaponize disclosed vulnerabilities against unpatched systems.

A Severe, Fast-Moving Vulnerability

The flaw, tracked as CVE-2026-59310, carries a CVSS score of 9.8 — near the maximum severity rating — and allows a malicious actor to execute arbitrary code on affected vCenter servers. VMware vCenter is the central management platform for VMware virtualized data centers, making a successful breach potentially catastrophic: compromising vCenter can hand an attacker control over an organization's entire virtual server infrastructure at once, rather than a single machine.

QUIRSO researchers Maike Orlikowski, Çağatay Yürekli, and Denis Szadkowski assessed with moderate confidence that the campaign is operated by a Chinese-speaking actor likely working in the UTC+08:00 time zone. Their attribution rests on Chinese-language artifacts found in attacker-created scripts, apparent reuse of research from a Chinese security publication, repeated use of Chinese-language tools and management software, a victim pattern that notably excludes mainland China, and activity timing consistent with UTC+08:00 working hours.

Where the Damage Landed

Infections were scattered widely, with the heaviest concentrations in Germany (55 victims), the United States (41), Turkey (38), Iran (26), and France (25). The exploitation chain began with the cron daemon logging a malformed cron file, followed by a curl or wget command retrieving a backdoor payload from a remote server before the attackers removed traces of the log file — standard tradecraft for establishing persistent access while minimizing forensic footprint.

A Second, Related Vulnerability in Play

QUIRSO also documented active exploitation of a second flaw, CVE-2026-59309, an authentication bypass vulnerability disclosed alongside CVE-2026-59310. On at least one compromised vCenter Server Appliance, evidence showed exploitation consistent with CVE-2026-59309 as early as August 1, 2026, including the creation of an unauthorized administrative account — notably without any corresponding login event from the legitimate administrator account that technically created it. The attackers also conducted vSphere discovery via the REST API using a User-Agent string designed to masquerade as legitimate VMware Cloud Foundation Fleet management traffic. QUIRSO found no overlap between this CVE-2026-59309 activity and the separate CVE-2026-59310 exploitation chain on the same system, suggesting either two distinct operators or deliberately compartmentalized tooling.

Why This Matters Beyond the Numbers

The five-day gap between patch release and active exploitation is the detail worth internalizing. Organizations running vCenter in production environments — which includes a large share of enterprise and government virtualized infrastructure — had almost no buffer between Broadcom's disclosure and real-world attacks. The eventual payload, a variant derived from the Babuk ransomware family, means affected organizations aren't just facing espionage or data theft but potential operational disruption through encryption of virtualized workloads.

For any organization running VMware vCenter, the practical takeaway is unambiguous: patching CVE-2026-59310 and CVE-2026-59309 is no longer a routine maintenance item but an urgent priority, and administrators should audit for unauthorized admin accounts and unusual REST API traffic patterns that could indicate the account-creation technique QUIRSO documented, even if patches have since been applied.

Originally reported by The Hacker News / QUIRSO. Read the original article for additional details.

View original source
Share: