Suspected China-nexus APT exploits VMware vCenter flaw, deploys Babuk-derived ransomware
In brief
This article walks through the technical indicators published by QUIRSO, the exploitation chain observed, and the lessons for DevSecOps teams managing critical virtualization infrastructure.
What CVE-2026-59310 is
CVE-2026-59310 is a directory traversal flaw in VMware vCenter Server that allows an unauthenticated remote attacker to execute arbitrary code. The vulnerability received a CVSS score of 9.8 out of 10, placing it at the maximum severity tier. The attack vector is the network, requires no user interaction, and exploits insufficient path validation in vCenter's file handling component.
Broadcom shipped the patch on July 29, 2026. Public disclosure happened the same day, giving attackers a five-day window before observed mass exploitation began. For a vulnerability of this severity, five days is enough for multiple distinct threat groups to attempt exploitation.
For DevSecOps professionals managing virtualization infrastructure, vCenter is an especially attractive target because:
- It controls all the VMs in the environment. - It has access to ESXi host credentials. - It is reachable from the management network. - Its compromise is, in practice, equivalent to datacenter compromise.
The QUIRSO chain exploits precisely that privileged position.
The attribution: China-nexus, not confirmed
QUIRSO published their analysis on Medium with a moderate confidence level. The attribution to a Chinese-speaking actor is based on five indicators:
1. **Chinese-language artifacts** in attacker-created scripts. File names and comment strings contain simplified Chinese characters. 2. **Reuse of research from a Chinese security publication.** The exploit code shows similarities to code published in a Chinese security blog, suggesting the actor reused public research from its own linguistic community. 3. **Repeated operational use of Chinese-language tools and management software.** Lateral movement tools and management dashboards deployed by the attacker are in simplified Chinese. 4. **Victimology excluding mainland China.** None of the 361 compromised IP addresses is located in mainland China, consistent with a state-aligned actor avoiding compromise of domestic infrastructure. 5. **Activity patterns compatible with UTC+08:00 working hours.** Timestamps of attacker activity correspond to normal working hours in China, Singapore, and Malaysia.
The APT attribution is not conclusive — QUIRSO states this explicitly — but the convergence of five independent indicators makes the hypothesis reasonable for defensive planning.
Geographic scope of the campaign
The campaign hit 361 unique IP addresses across 47 countries. Country distribution per QUIRSO:
- Germany: 55 - United States: 41 - Turkey: 38 - Iran: 26 - France: 25 - Rest: 176 spread across 42 additional countries
The concentration in Germany and the United States is notable but not definitive. Germany is one of the largest VMware vCenter markets in Europe, which partially explains the overrepresentation. The APT component suggests selected targets rather than opportunistic mass infection, but the total volume indicates an industrial-scale operation.
Exploitation chain observed
QUIRSO published specific technical detail on the chain. There are two distinct paths that converge on the same final objective.
### Path 1: exploitation of CVE-2026-59309
CVE-2026-59309 is an authentication bypass flaw in vCenter. QUIRSO evidence shows malicious activity consistent with CVE-2026-59309 exploitation beginning August 1, 2026, just three days after the initial patch. The first action was creation of an administrative account in vCenter, made from IP address 146.59.252[.]178.
Interesting: no login events were observed for the legitimate administrative account that supposedly created this new account. That suggests the attacker either compromised that account and used a method that does not generate auditable login events, or exploited a direct path to account creation without going through the standard authentication API.
After creating the account, the attacker performed vSphere discovery via the REST API on August 3, using User-Agent strings like `GoodMoodle-VCFleet/1.0`, attempting to disguise the activity as legitimate VMware traffic. VCF Fleet is a centralized management capability introduced in VMware Cloud Foundation 9.0 to deploy, scale, patch, and operate multiple VCF instances. It covers VCF Operations, VCF Automation, vCenter, NSX Manager, vSphere Cluster, and workload domains. The falsified User-Agent attempts to pass as a legitimate VMware tool to avoid detection in logs.
The "vcenter_admin" account created during this phase was not used in subsequent attack phases, per QUIRSO. The attackers likely reserved it as additional persistence in case the primary RCE channel was detected and removed.
### Path 2: exploitation of CVE-2026-59310
This is the main path of the chain. The first observed activity was logging by the cron daemon (crond) of a malformed cron file called `zz-poc59310-syslog.log`. The file name is explicit: direct reference to the CVE identifier and the fact that it is a proof-of-concept after public disclosure.
The `-syslog.log` suffix also mimics the vCSA remote syslog file naming convention, but the file appears under `/etc/cron.d` rather than the configured syslog output directory. That suggests the attacker abused the vCSA syslog server to place files in a privileged execution location. Some files were malformed and not executed by cron, but at least one file did execute and placed the `linuxFile` backdoor on the system.
Next step in the chain: a `curl` command (or alternatively `wget`) to retrieve a backdoor from `5.34.177[.]38:9861`, execute it, and then delete the log file. The IP address and port are the attacker's command-and-control infrastructure.
### The linuxFile backdoor
The `linuxFile` implant is designed to provide remote command execution to the attacker. It establishes a connection to its controller over a WebSocket channel to receive instructions, executes them through `/bin/sh`, and transmits the results back.
WebSocket as a command-and-control channel is interesting from a defensive perspective. Persistent WebSocket connections are hard to distinguish from legitimate traffic in firewall logs, especially when the endpoint is on a standard port. For SOC analysts, looking for long-duration WebSocket connections from vCenter to external IPs is a useful indicator.
### Final payload: Babuk ransomware
The final phase of the chain is deployment of a Babuk-derived ransomware variant adapted for Linux. Original Babuk is a ransomware family whose source code leaked in 2021, giving rise to multiple variants. The version observed in this campaign appears to be one of those reused variants.
Original Babuk ransomware mainly targeted Windows environments, but the code leak facilitated the development of Linux variants that are now popular among operators attacking virtualization infrastructure. The reason is structural: encrypting VM disk files on an ESXi datastore is a high-impact target to affect the maximum number of systems in a single operation.
Publishable indicators of compromise
QUIRSO published several usable IoCs:
- **Source attack IPs**: 146.59.252[.]178 (admin account creation), 5.34.177[.]38:9861 (backdoor download server). - **File hash**: for `linuxFile` (not included in the public article but shareable under request with research organizations). - **Anomalous User-Agent**: `GoodMoodle-VCFleet/1.0` and similar variants attempting to impersonate VCF Fleet. - **File names**: any file under `/etc/cron.d/` following the `zz-poc<CVE-id>-syslog.log` pattern. - **Anomalous processes**: any `linuxFile`, `curl`, or `wget` process executed from `/etc/cron.d/`.
Mitigations for DevSecOps teams
**1. Immediate vCenter patching.** The priority is confirming all vCenter Server Appliance (vCSA) instances have Broadcom's July 29, 2026 patch or later applied. For HA or linked mode environments, verify all nodes.
```bash # Verify vCenter version from SSH or VAMI # In the VAMI console (port 5480): # Version must show patch 7.0 U3o or 8.0 U3e or later depending on line ```
**2. Management network segmentation.** vCenter must not be reachable from the internet or from general corporate networks. Access restricted to a dedicated management VLAN with a bastion or jump host. This is one of the most repeated and least implemented recommendations.
**3. Syslog monitoring.** Enable syslog forwarding from vCenter to a SIEM with alerts on any write to `/etc/cron.d/`. This is the route attackers abused to place malicious files.
**4. Detection of the specific chain.** SIEM rules for:
```spl # SPL rule (Splunk) to detect file creation in /etc/cron.d/ index=vcsa sourcetype=syslog "/etc/cron.d/zz-poc" | stats count by host, file_name ```
**5. Administrative account audit.** Review all administrative accounts in vCenter, especially any account created between August 1 and 15, 2026. The "vcenter_admin" account is the signature of the CVE-2026-59309 chain.
**6. Outbound firewall rules.** Block long-duration WebSocket connections from vCenter to external IPs. vCenter has a known set of legitimate endpoints for updates and telemetry; anything else should generate an alert.
**7. REST API deactivation for discovery.** If your organization does not use the vSphere REST API for discovery, disabling it reduces the lateral attack surface.
What the chain teaches us
Three important lessons from this case:
**Lateral movement through syslog is elegant.** Attackers abused a channel administrators have on their allow list. Placing malicious files under `/etc/cron.d/` via syslog is a technique that evades most detections because syslog is expected traffic.
**Attribution does not require certainty.** QUIRSO published with moderate confidence and that was enough to inform defensive decisions. Waiting for confirmed attribution before acting is a strategic mistake. When multiple indicators converge on a reasonable hypothesis, planning against that hypothesis is reasonable.
**The five-day window was enough.** Broadcom published the patch and attackers began operating before most organizations completed their patching cycle. This is consistent with the modern ransomware pattern: campaigns move at internet speed.
Immediate checklist
- [ ] All vCenter instances patched to the July 29, 2026 version. - [ ] vCenter not reachable from the internet or general networks. - [ ] vCenter syslog forwarded to SIEM. - [ ] Detection rules for `/etc/cron.d/zz-poc*` active. - [ ] Administrative account audit completed. - [ ] Outbound WebSocket firewall rules applied. - [ ] Offline backups of critical VMs verified and tested. - [ ] ESXi-specific ransomware response plan documented.
Call to action
Does your organization manage critical VMware vCenter infrastructure? The QUIRSO chain is the new baseline of what a sophisticated APT can do against virtualization infrastructure. Management network segmentation, accelerated patching, and syslog-based detection are the three controls that separate victims from those who close the door before the attack.
Every week we publish technical analyses of APT campaigns with actionable indicators for your DevSecOps team. Follow X-Ops on X, Instagram, LinkedIn, and YouTube, and Hacker Dreams on X, Instagram, and LinkedIn, so you don't miss the next analysis.
---
*Sources: QUIRSO analysis published on Medium (medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d), The Hacker News original report.*