Hackers from the Scattered Spider are targeting virtual environments, carrying out attacks on VMware ESXi hypervisors of companies in the United States belonging to the retail, aviation, transportation and insurance sectors.
See also: VMware fixed vulnerabilities used at Pwn2Own Berlin 2025

According to the Google Threat Intelligence Group (GITG) , attackers continue to use their usual tactics, which are not based on exploiting vulnerabilities, but on well-executed social engineering , “ bypassing even mature security programs .” The researchers report that the attack begins by intercepting the identity of an employee when communicating with the IT help desk. The attacker’s goal is to convince the technician to change the employee’s Active Directory password , thus securing initial access
This allows the Scattered Spider team to scan network devices for IT documentation that reveals high-value targets, such as domain administrator or VMware vSphere administrator names, as well as security groups with administrative in the virtual environment.
At the same time, they scan for Privileged Access Management (PAM) solutions, which may contain sensitive data useful for further penetration into critical network assets.
Scattered Spider then seeks to gain access to the company's VMware vCenter Server Appliance (vCSA) — a virtual machine that enables management of VMware vSphere, which include the ESXi hypervisor to control all virtual machines on a physical server.
See also: BERT Ransomware disables ESXi virtual machines
This level of access allows them to enable SSH connections to ESXi hosts and reset root passwords. They also perform a so-called “disk-swap” attack to extract the critical NTDS.dit Active Directory database.

A disk-swap attack occurs when attackers power down a Domain Controller and detach its virtual disk, which they then attach to another, unattended virtual machine that they control. After copying sensitive data (e.g., the NTDS.dit file), they reverse the process and power the Domain Controller.
It is worth noting that the level of control that the Scattered Spider team gains over the virtual infrastructure allows them to manage all available assets, including backup machines, which are completely de-duplicated by backup jobs, snapshots, and repositories.
In the final stage of the attack, the Scattered Spider group leverages the SSH access it has gained to transfer and install ransomware executables to encrypt all virtual machine (VM) files located in the datastores.
To help organizations protect themselves from these types of attacks, Google has published a technical article that describes the stages of a Scattered Spider attack, explains why it is so effective, and suggests actions that can be taken to detect the breach early.
See also: Vulnerability in VMware Tools allows file compromise
Although the UK's National Crime Agency has arrested four people suspected of being members of the group, malicious activity — originating from other groups with similar characteristics — has not diminished.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
