BlackByte Ransomware Exploits VMware ESXi Flaw Launching A New Wave of Cyber Threats

New Products

Summary

The BlackByte ransomware group is back, and this time, theyre exploiting a newly patched vulnerability in VMware ESXi hypervisors, raising alarm across the cybersecurity landscape. By leveraging valid credentials to access a victim’s VPN, BlackByte has managed to reduce visibility from the organizations endpoint detection and response (EDR) systems, making their attacks even more stealthy. Despite some efforts to combat BlackByte—such as the release of a decryptor by Trustwave in October 2021—the group has continued to refine its operations, employing custom tools like ExByte for data exfiltration before encryption. As they continue to adapt and refine their techniques, organizations must remain vigilant, ensuring their systems are patched promptly and that security measures are robust enough to counter these evolving attacks. As ransomware groups like BlackByte continue to evolve, leveraging new vulnerabilities and techniques, organizations must stay ahead of the curve to protect their critical infrastructure.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M