ESXiArgs is ransomware that targets VMware ESXi hypervisors and became widely known during a large-scale campaign in early 2023 affecting exposed, unpatched servers across multiple countries, particularly in Europe and North America. The campaign has been associated with exploitation of CVE-2021-21974, a remote code execution flaw in the ESXi OpenSLP service, allowing attackers to compromise vulnerable internet-facing hosts and deploy the locker without authentication.
Once executed, ESXiArgs encrypts ESXi and virtual machine-related files, including configuration and disk files, which can render hosted virtual machines unusable and disrupt many business services at once. It also creates per-file metadata used during encryption and leaves ransom notes for victims. Analysis indicates the binary itself is relatively simple and depends on operator-supplied parameters and external scripting to iterate over target files. The malware requires the path to an RSA public key file as an argument and uses the Sosemanuk cipher implementation in its encryption workflow. Like other ESXi-focused ransomware, it is intended for enterprise server environments rather than consumer endpoints.
ESXiArgs is notable for targeting virtualization infrastructure, where a single compromised hypervisor can impact numerous guest systems simultaneously. Public reporting initially speculated that it was derived from Babuk, but later comparative analysis found little meaningful similarity beyond limited overlap such as use of the same cipher implementation, making strong lineage claims unsupported. Recovery tooling was released for some victims, though later variants were reported that were not recoverable with the initial script.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The ransomware dubbed as “ESXiArgs” is being deployed by exploiting a two-year-old remote code execution vulnerability. Tracked as CVE-2021-21974, the vulnerability is caused by a heap overflow issue in the OpenSLP service and this is being exploited by unauthenticated threat actors in low-complexity attacks. | The Cybersecurity and Infrastructure Security Agency (CISA) of the United States has released a recovery script for organizations that have fallen victim to ESXiArgs ransomware. The ESXiArgs ransomware encrypts configuration files on vulnerable ESXi servers, potentially rendering virtual machines (VMs) unusable.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
the attackers can greatly impact multiple services and machines ... tend to run specific commands aimed at interacting with ESXi systems
ESXiArgs also uses an external shell script to search files and provide arguments to the esxcli, so there is no native find_files_recursive function to compare.
The ransomware dubbed as “ESXiArgs” is being deployed by exploiting a two-year-old remote code execution vulnerability. Tracked as CVE-2021-21974, the vulnerability is caused by a heap overflow issue in the OpenSLP service and this is being exploited by unauthenticated threat actors in low-complexity attacks.
Lockbit , ESXiArgs , BlackCat, or Gwisin , the malware has the ability to self-delete after execution.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware targeting ESXi infrastructure, associated in the content with exploitation of exposed OpenSLP services or VMware vCenter servers.
An ESXi-targeting ransomware locker used in a February campaign against unpatched cloud services. The article says it is often misattributed as Babuk-derived, but only shares the same open-source Sosemanuk implementation and otherwise differs substantially.
ESXi-focused ransomware with a very minimal encryptor. The binary requires an external RSA public key file and cannot encrypt a whole directory on its own, relying on scripts to iterate over files. The content says the name comes from the TTPs of actors using it rather than unique binary capabilities.
Ransomware targeting VMware ESXi servers; associated with a large-scale early-2023 campaign and reported exploitation of an ESXi vulnerability for initial access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.