BlackByte Ransomware Exploits VMware ESXi Flaw Launching A New Wave of Cyber Threats
Summary
The BlackByte ransomware group is back, and this time, theyre exploiting a newly patched vulnerability in VMware ESXi hypervisors, raising alarm across the cybersecurity landscape. By leveraging valid credentials to access a victim’s VPN, BlackByte has managed to reduce visibility from the organizations endpoint detection and response (EDR) systems, making their attacks even more stealthy. Despite some efforts to combat BlackByte—such as the release of a decryptor by Trustwave in October 2021—the group has continued to refine its operations, employing custom tools like ExByte for data exfiltration before encryption. As they continue to adapt and refine their techniques, organizations must remain vigilant, ensuring their systems are patched promptly and that security measures are robust enough to counter these evolving attacks. As ransomware groups like BlackByte continue to evolve, leveraging new vulnerabilities and techniques, organizations must stay ahead of the curve to protect their critical infrastructure.