ESXiArgs attack vector unclear as infections continue
ESXiArgs has turned into one of the highest-profile threat campaigns in recent memory, despite only having a moderate scale. ESXiArgs is the name of the ransomware campaign involving a series of attacks against servers with vulnerable instances of VMware ESXi. Initial attack reports came in early February, and an updated advisory from French cyber agency CERT-FR listed vulnerabilities CVE-2020-3992 and CVE-2021-21974 as possible attack vectors. Thousands of servers have apparently been infected by the ransomware so far. The Shadowserver Foundation CEO Piotr Kijewski told TechTarget Editorial last week that ESXiArgs lacks the scale of Log4Shell and ProxyShell threats, but it has perhaps proven notable because it’s an enterprise-focused campaign that spread quickly. There are also looming questions about ESXiArgs’ attack vector and which threat actor — or actors — is behind the campaign.