Cybersecurity researchers have linked the active exploitation of a recently patched VMware vCenter vulnerability to a suspected China nexus advanced persistent threat group that has been deploying backdoors, persistence mechanisms and Babuk derived ransomware on compromised environments. According to German incident response company QUIRSO, the campaign abuses CVE 2026 59310, a critical directory traversal vulnerability in Broadcom VMware vCenter Server with a CVSS score of 9.8 that allows attackers to execute arbitrary code remotely. Broadcom released security updates for the flaw on July 29, 2026, but researchers found that exploitation began only five days after the vulnerability became publicly known. QUIRSO assessed with moderate confidence that the activity originated from a Chinese speaking threat actor operating in the UTC plus 08:00 time zone based on multiple indicators, including Chinese language artifacts found in attacker scripts, reuse of research from a Chinese security publication, repeated use of Chinese language tools and management software, victim organizations located outside mainland China and activity patterns matching working hours in Chinese speaking regions. Researchers estimate that the campaign has compromised 361 unique victim IP addresses across 47 countries, with Germany, the United States, Turkey, Iran and France recording the highest number of affected systems.
The investigation also uncovered evidence that one targeted VMware vCenter Server Appliance was attacked using both CVE 2026 59310 and CVE 2026 59309, an authentication bypass vulnerability that has also experienced active scanning activity. Researchers found signs of exploitation of CVE 2026 59309 as early as August 1, 2026, resulting in the creation of a new administrative account on the affected vCenter environment. The account creation originated from the IP address 146.59.252.178 and included vSphere discovery activity through the REST API using a User Agent string designed to resemble VMware software. Although the attacker created a new administrator account named vcenter_admin, investigators found no evidence that it was used during the later phases of the compromise, suggesting separate exploitation paths. In the exploitation of CVE 2026 59310, attackers abused the cron daemon to execute a malicious cron file named zz poc59310 syslog.log before downloading a backdoor from an external server. The malware, identified as linuxFile, establishes encrypted communications with its command and control infrastructure using WebSocket connections, executes remote shell commands, automatically reconnects after interruptions and installs persistence through systemd services and cron jobs.
QUIRSO reported that the threat actor relied heavily on cron based automation to deploy additional payloads and maintain long term access to compromised systems. Researchers observed shell scripts downloading architecture specific reverse SSH tools, creating staging directories, modifying permissions and launching malware from multiple remote servers. The campaign also created cron jobs that impersonated legitimate VMware services while installing JSP web shells, establishing remote SSH access channels and executing credential theft routines. The attackers created additional privileged accounts including adminuser and vcadmin, modified VMware Directory Service using compromised administrative credentials and configured unrestricted passwordless sudo access for selected service accounts. Researchers also documented scripts that extracted VMware directory credentials, queried system information and performed privileged directory modifications before using the vSphere API for infrastructure discovery. The compromise ultimately extended beyond the vCenter server to ESXi hosts, where attackers created local administrative accounts to prepare systems for ransomware deployment while simultaneously attempting to reduce forensic visibility and blend malicious activity with normal VMware operations.
The final stage of the intrusion involved deployment of ransomware that encrypted files on ESXi hosts using the .babyk extension, which is commonly associated with Babuk derived ransomware families. While the ransomware was successfully deployed on the investigated system, QUIRSO stated that it remains unclear whether encryption represented the primary objective of the campaign or whether it was introduced to complicate attribution and hinder forensic investigations by encrypting valuable log files. Researchers noted that exploiting CVE 2026 59310 provided immediate root level code execution on VMware vCenter Server Appliance, allowing unrestricted access without first compromising lower privileged accounts. This enabled the attackers to establish persistence, deploy multiple malware components, perform credential theft, expand access across VMware infrastructure and eventually launch ransomware on ESXi hosts.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





