CISA thinks it has a fix to the global ESXi ransomware attacks

ransomware avast
(Image credit: Avast)

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a script on GitHub aimed at helping the VMware ESXi ransomware attack victims rebuild their endpoints.

Thousands of VMware ESXi servers have recently been targeted across Europe and North America, with initial reports mentioning some 500 victims, and newer assessments putting the number at 2,800. 

The unnamed attackers scanned VMware ESXi servers in search of CVE-2021-21974, a known vulnerability that was patched by the company two years ago. Those that were vulnerable ended up infected with ransomware.

Failed encryption campaign

However, the cybercrime campaign seems to have been mostly unsuccessful, as the ransomware did not encrypt flat files which hold data for virtual disks.

Two researchers from YoreGroup Tech Team found a way to use those files to rebuild virtual machines. While many were successful in using their method to recover their servers, the process is allegedly relatively complex, prompting CISA to jump in and help automate the process with a script. 

"CISA is aware that some organizations have reported success in recovering files without paying ransoms. CISA compiled this tool based on publicly available resources, including a tutorial by Enes Sonmez and Ahmet Aykac," the agency said. "This tool works by reconstructing virtual machine metadata from virtual disks that were not encrypted by the malware."

While immensely helpful, the script still needs to be carefully considered, CISA says. Administrators should first review it, to eliminate any possible complications. Backing up the files before engaging in any recovery process is also highly welcome. 

"While CISA works to ensure that scripts like this one are safe and effective, this script is delivered without warranty, either implicit or explicit." the agency concluded. "Do not use this script without understanding how it may affect your system. CISA does not assume liability for damage caused by this script."

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A person holding out their hand with a digital AI symbol.
This ransomware gang is using SSH tunnels to target VMware appliances
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
data recovery
Ghost ransomware has hit firms in over 70 countries, FBI and CISA warn
Avast cybersecurity
Hackers are hijacking government software to access sensitive servers
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Interlock ransomware attacks highlight need for greater security standards on critical infrastructure
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
Latest in Security
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Data leak
Top California sperm bank suffers embarrassing leak
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Latest in News
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years
The Nanoleaf PC Screen Mirror Lightstrip being used on a desktop computer.
Mac gaming could get an intriguing boost – but not in the way you'd expect
Snapdragon G Series
Qualcomm poised to muscle in on AMD's territory with powerful gaming handheld processors