HackMyIP
← Back to News
2026-08-17 The Hacker News

China-Linked APT Exploits VMware vCenter Bug to Deploy Babuk Ransomware

APTRansomwareVulnerability

A suspected China-nexus advanced persistent threat (APT) has been weaponizing a critical directory-traversal flaw in Broadcom VMware vCenter to deliver Babuk-derived ransomware across at least 47 countries. Researchers at German incident-response firm QUIRSO traced the campaign to CVE-2026-59310, which carries a CVSS score of 9.8 and was patched by Broadcom on July 29, 2026. Exploitation began just five days later, ultimately compromising 361 unique victim IP addresses, with the heaviest concentration in Germany (55), the United States (41), Turkey (38), Iran (26), and France (25). The firm rated attribution as moderate confidence, pointing to Chinese-language artifacts in attacker scripts, reuse of Chinese security-research output, repeated use of Chinese management tools, victimology excluding mainland China, and activity clustered within the UTC+08:00 working window.

QUIRSO analysts Maike Orlikowski, Çağatay Yürekli, and Denis Szadkowski also observed a second flaw, CVE-2026-59309, an authentication-bypass vulnerability that triggered active scanning as early as August 1, 2026. On one compromised vCenter Server Appliance, attackers originating from 146.59.252[.]178 created a new administrative account named "vcenter_admin" on August 1 and then issued vSphere discovery requests through the REST API on August 3 using a forged User-Agent string, "GoodMoodle-VCFleet/1.0," designed to blend with legitimate VCF Fleet 9.0 management traffic. Researchers confirmed no overlap between the two attack chains on the same host, noting that the rogue administrator account was not reused in subsequent intrusion phases linked to CVE-2026-59310.

The CVE-2026-59310 exploitation chain gave the operators arbitrary code execution, enabling lateral movement, credential harvesting, and the deployment of a ransomware strain derived from the leaked Babuk source code. Organizations running unpatched vCenter instances exposed to the internet remain the primary risk and should be audited immediately; defenders can verify exposed surface area with a port scanner and confirm administrative-domain ownership through a WHOIS lookup. Any newly created vCenter accounts, especially those appearing outside change-control windows, should be treated as indicators of compromise and investigated as part of an active incident-response engagement. Security teams are urged to apply Broadcom's July 29 patch, hunt for the "GoodMoodle-VCFleet/1.0" User-Agent in proxy and vCenter logs, and segment vCenter management interfaces from production traffic to limit blast radius.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →