CVE-2024-37085
published 2024-06-25CVE-2024-37085: VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an…
PriorityP187high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2024-08-20
Exploited in the wild
EPSS
26.77%
97.8th percentile
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 4.0 < 5.2 | 5.2 |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
Detection & IOCsextracted from sources · hover to see the quote
command/c ping 1.1.1[.]1 -n 10 > Nul & fsutil file setZeroData offset=0 length=503808 c:\windows\host.exe & Del c:\windows\host.exe /F /Q↗
- →Monitor for creation of an Active Directory group named 'ESX Admins' (or 'ESXi Admins') on domain-joined ESXi hosts, especially if the group was recently re-created after deletion — this is the core exploitation mechanism for CVE-2024-37085. ↗
- →Detect NTLM authentication anomalies on ESXi/Windows hosts: threat actor primarily used NTLM while legitimate users used Kerberos — a divergence in authentication protocol usage is a lateral movement indicator. ↗
- →Detect the BlackByte ransomware self-deletion command pattern: use of 'fsutil file setZeroData' followed by 'Del /F /Q' on the ransomware binary, preceded by a ping delay loop. ↗
- →Detect the BlackByte ransomware execution pattern: 'host.exe' launched from C:\Windows with '-s' parameter followed by an 8-digit numeric string and 'svc' argument, which installs ransomware as a service. ↗
- →Use Qualys QID 216333 and QID 216331 to detect CVE-2024-37085 on VMware ESXi 8.0 and 7.0 assets respectively. ↗
- ·CVE-2024-37085 exploitation requires the attacker to first obtain high AD privileges (e.g., Domain Admin) before they can create or re-create the 'ESX Admins' group — the vulnerability is not remotely exploitable without prior privilege escalation. ↗
- ·ESXi 7.0 and VMware Cloud Foundation 4.x have no patch planned for CVE-2024-37085; administrators must rely on configuration workarounds for AD group privilege defaults. ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck6.8MEDIUM
cisa7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-485m-923f-95wx: VMware ESXi contains an authentication bypass vulnerability
ghsa_unreviewed·2024-06-25
CVE-2024-37085 [MEDIUM] CWE-287 GHSA-485m-923f-95wx: VMware ESXi contains an authentication bypass vulnerability
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
VulnCheck
VMware ESXi Authentication Bypass Vulnerability
vulncheck·2024·CVSS 6.8
CVE-2024-37085 [MEDIUM] CWE-305 VMware ESXi Authentication Bypass Vulnerability
VMware ESXi Authentication Bypass Vulnerability
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
Affected: VMware ESXi
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.fortiguard.com/outbreak-alert/akira-ransomware; https://attackerkb.com/topics/2llWJbMF0o/cve-2024-37085; https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervi
CISA
VMware ESXi Authentication Bypass Vulnerability
cisa·2024-07-30·CVSS 7.2
CVE-2024-37085 [HIGH] CWE-305 VMware ESXi Authentication Bypass Vulnerability
Vulnerability: VMware ESXi Authentication Bypass Vulnerability
Affected: VMware ESXi
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505; https://nvd.nist.gov/vuln/detail/CVE-2024-37085
Remediation Due Date: 2024-08-20
No detection rules found.
No public exploits indexed.
Mandiant
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape
blogs_mandiant·2026-03-16
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape
## Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark
## Introduction
Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region. In recent years ransomware operations have evolved, creating a robust ecosystem that has lowered the barrier to entry via the commoditization and specialization of the supporting underground communities, w
Mandiant
Ransomware Tactics, Techniques, and Procedures in a Shifting Threat Landscape
blogs_mandiant·2026-03-16
Ransomware Tactics, Techniques, and Procedures in a Shifting Threat Landscape
Threat Intelligence
# Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape
March 16, 2026
##### Google Threat Intelligence Group
##### Google Threat Intelligence
Visibility and context on the threats that matter most.
Contact Us & Get a Demo
Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark
### Introduction
Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region. In recent years ransomware operations have evolved, creating a robust ecosystem that has lowered the barrier to entry via the commoditiza
Bleepingcomputer
The Hidden Risk in Virtualization: Why Hypervisors are a Ransomware Magnet
blogs_bleepingcomputer·2025-12-16
The Hidden Risk in Virtualization: Why Hypervisors are a Ransomware Magnet
## The Hidden Risk in Virtualization: Why Hypervisors are a Ransomware Magnet
## Huntress Labs
Author: Dray Agha, Senior Manager, Hunt & Response, at Huntress Labs
Hypervisors are the backbone of modern virtualized environments, but when compromised, they can become a force multiplier for attackers. A single breach at this layer can put dozens or even hundreds of virtual machines at risk simultaneously. Unlike traditional endpoints, hypervisors often operate with limited visibility and protections, meaning conventional security tools may be blind to an attack until it is too late.
From our vantage point in the SOC and threat-hunting space at Huntress, we are seeing adversaries increasingly target hypervisors to deploy ransomware at scale. Specifically, in 2025, Huntress case data revea
Huntress
Hardening the Hypervisor: Practical Defenses Against Ransomware Targeting ESXi
blogs_huntress·2025-12-08
Hardening the Hypervisor: Practical Defenses Against Ransomware Targeting ESXi
Hypervisors are the backbone of modern virtualized environments, but when compromised, they can become a force multiplier for attackers. A single breach at this layer can put dozens or even hundreds of virtual machines at risk simultaneously. Unlike traditional endpoints, hypervisors often operate with limited visibility and protections, meaning conventional security tools may be blind to an attack until it is too late.
From our vantage point in the SOC and threat-hunting space at Huntress, we're seeing adversaries increasingly target hypervisors to deploy ransomware at scale. Specifically, in 2025, Huntress case data revealed a stunning surge in hypervisor ransomware: its role in malicious encryption rocketed from just 3% in the first half of the year to 25% so far in the second half. Th
Qualys
Understanding the Impact of Scattered Spider on the Airline & Transportation Industry
blogs_qualys·2025-07-21·CVSS 7.8
[HIGH] Understanding the Impact of Scattered Spider on the Airline & Transportation Industry
## Table of Contents
What is Scattered Spider?
Airline Industry Asset Risks:
Insights from the Threat Research Unit and Key Findings:
Key Impacts and Recommendations:
Measure, Communicate, and Eliminate Your Risk from Scattered Spider with Qualys
In June, the FBI publicly warned that Scattered Spider is actively targeting the aviation and transportation sectors, including well-known airlines and their third-party IT vendors. In this post, we will provide a brief overview of Scattered Spider, insights gathered by our research team into the vulnerabilities they target, and how organizations can protect themselves.
## What is Scattered Spider?
Scattered Spider is a financially motivated hacking collective (also known as UNC3944, Octo Tempest, Scatter Swine, and Star Fraud), mostly com
Qualys
Understanding the Impact of Scattered Spider on the Airline & Transportation Industry | Qualys
blogs_qualys·2025-07-21·CVSS 7.8
[HIGH] Understanding the Impact of Scattered Spider on the Airline & Transportation Industry | Qualys
#### Table of Contents
- What is Scattered Spider?
- Airline Industry Asset Risks:
- Insights from the Threat Research Unit and Key Findings:
- Key Impacts and Recommendations:
- Measure, Communicate, and Eliminate Your Risk from Scattered Spider with Qualys
In June, the FBI publicly warned that Scattered Spider is actively targeting the aviation and transportation sectors, including well-known airlines and their third-party IT vendors. In this post, we will provide a brief overview of Scattered Spider, insights gathered by our research team into the vulnerabilities they target, and how organizations can protect themselves.
## What is Scattered Spider?
Scattered Spider is a financially motivated hacking collective (also known as UNC3944, Octo Tempest, Scatter Swine, and Star Fraud), mo
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Securelist
Non-mobile threat statistics for Q3 2024
blogs_securelist·2024-11-29
Non-mobile threat statistics for Q3 2024
Table of Contents
- Quarterly figures
- Ransomware
- Miners
- Attacks on macOS
- IoT threat statistics
- Attacks via web resources
- Local threats
Authors
- AMR
IT threat evolution in Q3 2024
IT threat evolution in Q3 2024. Non-mobile statistics
IT threat evolution in Q3 2024. Mobile statistics
The statistics presented here are based on detection verdicts by Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
In Q3 2024:
- Kaspersky solutions successfully blocked more than 652 million cyberattacks originating from various online resources.
- Web Anti-Virus detected 109 million unique links.
- File Anti-Virus blocked more than 23 million malicious and potentially unwanted objects.
- More than 90,000 users experience
Securelist
IT threat evolution in Q3 2024. Non-mobile statistics
blogs_securelist·2024-11-29
IT threat evolution in Q3 2024. Non-mobile statistics
Table of Contents
Quarterly figures
Ransomware
Quarterly trends and highlights
Progress in law enforcement
Vulnerability exploitation attacks
High-profile incidents
The most prolific groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 countries attacked by ransomware Trojans
TOP 10 most common families of ransomware Trojans
Miners
Number of new modifications
Users attacked by miners
Geography of miner attacks
TOP 10 countries attacked by miners
Attacks on macOS
TOP 20 threats to macOS
Geography of threats to macOS
TOP 10 countries and territories by share of attacked users
IoT threat statistics
TOP 10 threats downloaded to IoT devices:
Attacks on IoT honeypots
Attacks via web resources
Countries that
Talos
Talos IR trends Q3 2024: Identity-based operations loom large
blogs_talos·2024-10-24
Talos IR trends Q3 2024: Identity-based operations loom large
Threat actors are increasingly conducting identity-based attacks across a range of operations that are proving highly effective, with credential theft being the main goal in a quarter of incident response engagements.
These attacks were primarily facilitated by living-off-the-land binaries (LoLBins), open-source applications, command line utilities, and common infostealers, highlighting the relative ease at which these operations can be carried out. In addition to outright credential harvesting, we also saw password spraying and brute force attacks, adversary-in-the-middle (AitM) operations, and insider threats, underscoring the variety of ways in which actors are compromising users' identities.
Identity-based attacks are concerning because they often involve actors launching internal at
Talos
Talos IR trends Q3 2024: Identity-based operations loom large
blogs_talos·2024-10-24
Talos IR trends Q3 2024: Identity-based operations loom large
## Talos IR trends Q3 2024: Identity-based operations loom large
Threat actors are increasingly conducting identity-based attacks across a range of operations that are proving highly effective, with credential theft being the main goal in a quarter of incident response engagements.
These attacks were primarily facilitated by living-off-the-land binaries (LoLBins), open-source applications, command line utilities, and common infostealers, highlighting the relative ease at which these operations can be carried out. In addition to outright credential harvesting, we also saw password spraying and brute force attacks, adversary-in-the-middle (AitM) operations, and insider threats, underscoring the variety of ways in which actors are compromising users' identities.
Identity-based attacks are
Talos
Akira ransomware continues to evolve
blogs_talos·2024-10-21
Akira ransomware continues to evolve
## Akira ransomware continues to evolve
Akira continues to cement its position as one of the most prevalent ransomware operations in the threat landscape, according to Cisco Talos’ findings and analysis.
Their success is partly due to the fact that they are constantly evolving. For example, after Akira already developed a new version of their ransomware encryptor earlier in the year, we just recently observed another novel iteration of the encryptor targeting Windows and Linux hosts alike.
Previously, Akria typically employed a double-extortion tactic in which critical data is exfiltrated prior to the compromised victim systems becoming encrypted. Beginning in early 2024, Akira appeared to be sidelining the encryption tactics, focusing on data exfiltration only. We assess with low to mo
Talos
Akira ransomware continues to evolve
blogs_talos·2024-10-21
Akira ransomware continues to evolve
Akira continues to cement its position as one of the most prevalent ransomware operations in the threat landscape, according to Cisco Talos’ findings and analysis.
Their success is partly due to the fact that they are constantly evolving. For example, after Akira already developed a new version of their ransomware encryptor earlier in the year, we just recently observed another novel iteration of the encryptor targeting Windows and Linux hosts alike.
Previously, Akria typically employed a double-extortion tactic in which critical data is exfiltrated prior to the compromised victim systems becoming encrypted. Beginning in early 2024, Akira appeared to be sidelining the encryption tactics, focusing on data exfiltration only. We assess with low to moderate confidence that this shift was due
Talos
BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks
blogs_talos·2024-08-28·CVSS 6.8
CVE-2024-37085 [MEDIUM] BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks
- The BlackByte ransomware group continues to leverage tactics, techniques and procedures (TTPs) that have formed the foundation of its tradecraft since its inception, continuously iterating its use of vulnerable drivers to bypass security protections and deploying a self-propagating, wormable ransomware encryptor.
- In recent investigations, Talos IR has also observed BlackByte using techniques that depart from their established tradecraft, such as exploiting CVE-2024-37085 – an authentication bypass vulnerability in VMware ESXi – shortly after it was disclosed and using a victim’s authorized remote access mechanism rather than deploying a commercial remote administration tool like AnyDesk.
- Talos IR observed a new iteration of the BlackByte encryptor that appends the file extension “bla
Talos
BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks
blogs_talos·2024-08-28·CVSS 6.8
[MEDIUM] BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks
## BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks
The BlackByte ransomware group continues to leverage tactics, techniques and procedures (TTPs) that have formed the foundation of its tradecraft since its inception, continuously iterating its use of vulnerable drivers to bypass security protections and deploying a self-propagating, wormable ransomware encryptor.
In recent investigations, Talos IR has also observed BlackByte using techniques that depart from their established tradecraft, such as exploiting CVE-2024-37085 – an authentication bypass vulnerability in VMware ESXi – shortly after it was disclosed and using a victim’s authorized remote access mechanism rather than deploying a commercial remote administration tool like
Tenable
Cybersecurity Snapshot: Guide Unpacks Event-Logging Best Practices, as FAA Proposes Stronger Cyber Rules for Airplanes
blogs_tenable·2024-08-23
Cybersecurity Snapshot: Guide Unpacks Event-Logging Best Practices, as FAA Proposes Stronger Cyber Rules for Airplanes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
5th August – Threat Intelligence Report
blogs_checkpoint·2024-08-05
CVE-2017-0938 5th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 5th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 5th August, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
American blood donation center OneBlood has been a victim of a ransomware attack that caused disruption to its software system, affecting operations across more than 350 hospitals in Florida, Georgia, and the Carolinas. The attack has forced the organization to operate at reduced capacity and manually process blood donations,
Bleepingcomputer
CISA warns of VMware ESXi bug exploited in ransomware attacks
blogs_bleepingcomputer·2024-07-30·CVSS 6.8
CVE-2024-37085 [MEDIUM] CISA warns of VMware ESXi bug exploited in ransomware attacks
## CISA warns of VMware ESXi bug exploited in ransomware attacks
## Sergiu Gatlan
CISA has ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers against a VMware ESXi authentication bypass vulnerability exploited in ransomware attacks.
Broadcom subsidiary VMware fixed this flaw ( CVE-2024-37085 ) discovered by Microsoft security researchers on June 25 with the release of ESXi 8.0 U3.
CVE-2024-37085 allows attackers to add a new user to the 'ESX Admins' group—not present by default but can be added after gaining high privileges on the ESXi hypervisor—which will automatically be assigned full administrative privileges.
Even though successful exploitation would require user interaction and high privileges to pull off, and VMware rated the vulnerability as
Bleepingcomputer
Black Basta ransomware switches to more evasive custom malware
blogs_bleepingcomputer·2024-07-30·CVSS 6.8
[MEDIUM] Black Basta ransomware switches to more evasive custom malware
## Black Basta ransomware switches to more evasive custom malware
## Bill Toulas
The Black Basta ransomware gang has shown resilience and an ability to adapt to a constantly shifting space, using new custom tools and tactics to evade detection and spread throughout a network.
Black Basta is a ransomware operator who has been active since April 2022 and is responsible for over 500 successful attacks on companies worldwide.
The ransomware group follows a double-extortion strategy, combining data theft and encryption, and demands large ransom payments in the millions. The ransomware gang previously partnered with the QBot botnet to gain initial access to corporate networks.
However, after the QBot botnet was disrupted by law enforcement , Mandiant reports that the ransomware gang had to
Bleepingcomputer
Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks
blogs_bleepingcomputer·2024-07-29·CVSS 6.8
CVE-2024-37085 [MEDIUM] Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks
## Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks
## Sergiu Gatlan
Microsoft warned today that ransomware gangs are actively exploiting a VMware ESXi authentication bypass vulnerability in attacks.
Tracked as CVE-2024-37085 , this medium-severity security flaw was discovered by Microsoft security researchers Edan Zwick, Danielle Kuznets Nohi, and Meitar Pinto and fixed with the release of ESXi 8.0 U3 on June 25.
The bug enables attackers to add a new user to an 'ESX Admins' group they create, a user that will automatically be assigned full administrative privileges on the ESXi hypervisor.
"A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-cr
Threat Intel
BlackByte (BlackByte, Hecamede)
threat_intel
BlackByte (BlackByte, Hecamede)
# Threat Actor Profile: BlackByte
ATT&CK ID: G1043
Also known as: BlackByte, Hecamede
## Overview
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
## Techniques (TTPs)
### R
Greynoiseio
Storm⚡️Watch
blogs_greynoiseio
Storm⚡️Watch
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Huntress
Hardening the Hypervisor: Practical Defenses Against Ransomware Targeting ESXi | Huntress
blogs_huntress
Hardening the Hypervisor: Practical Defenses Against Ransomware Targeting ESXi | Huntress
Hypervisors are the backbone of modern virtualized environments, but when compromised, they can become a force multiplier for attackers. A single breach at this layer can put dozens or even hundreds of virtual machines at risk simultaneously. Unlike traditional endpoints, hypervisors often operate with limited visibility and protections, meaning conventional security tools may be blind to an attack until it is too late.
From our vantage point in the SOC and threat-hunting space at Huntress, we're seeing adversaries increasingly target hypervisors to deploy ransomware at scale. Specifically, in 2025, Huntress case data revealed a stunning surge in hypervisor ransomware: its role in malicious encryption rocketed from just 3% in the first half of the year to 25% so far in the second half. Th
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37085
2024-06-25
Published
2024-07-30
Added to CISA KEV
Exploited in the wild