HomeSecurityScattered Spider carries out massive attack on VMware ESXi

Scattered Spider carries out massive attack on VMware ESXi

Hackers from the Scattered Spider are targeting virtual environments, carrying out attacks on VMware ESXi hypervisors of companies in the United States belonging to the retail, aviation, transportation and insurance sectors.

See also: VMware fixed vulnerabilities used at Pwn2Own Berlin 2025

Scattered Spider VMware ESXi

According to the Google Threat Intelligence Group (GITG) , attackers continue to use their usual tactics, which are not based on exploiting vulnerabilities, but on well-executed social engineering , “ bypassing even mature security programs .” The researchers report that the attack begins by intercepting the identity of an employee when communicating with the IT help desk. The attacker’s goal is to convince the technician to change the employee’s Active Directory password , thus securing initial access

This allows the Scattered Spider team to scan network devices for IT documentation that reveals high-value targets, such as domain administrator or VMware vSphere administrator names, as well as security groups with administrative in the virtual environment.

At the same time, they scan for Privileged Access Management (PAM) solutions, which may contain sensitive data useful for further penetration into critical network assets.

Scattered Spider then seeks to gain access to the company's VMware vCenter Server Appliance (vCSA) — a virtual machine that enables management of VMware vSphere, which include the ESXi hypervisor to control all virtual machines on a physical server.

See also: BERT Ransomware disables ESXi virtual machines

This level of access allows them to enable SSH connections to ESXi hosts and reset root passwords. They also perform a so-called “disk-swap” attack to extract the critical NTDS.dit Active Directory database.

VMware ESXi

A disk-swap attack occurs when attackers power down a Domain Controller and detach its virtual disk, which they then attach to another, unattended virtual machine that they control. After copying sensitive data (e.g., the NTDS.dit file), they reverse the process and power the Domain Controller.

It is worth noting that the level of control that the Scattered Spider team gains over the virtual infrastructure allows them to manage all available assets, including backup machines, which are completely de-duplicated by backup jobs, snapshots, and repositories.

In the final stage of the attack, the Scattered Spider group leverages the SSH access it has gained to transfer and install ransomware executables to encrypt all virtual machine (VM) files located in the datastores.

To help organizations protect themselves from these types of attacks, Google has published a technical article that describes the stages of a Scattered Spider attack, explains why it is so effective, and suggests actions that can be taken to detect the breach early.

See also: Vulnerability in VMware Tools allows file compromise

Although the UK's National Crime Agency has arrested four people suspected of being members of the group, malicious activity — originating from other groups with similar characteristics — has not diminished.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS