Cybersecurity researchers have identified a suspected China-linked advanced persistent threat (APT) group exploiting a critical vulnerability in VMware vCenter Server to deploy ransomware derived from Babuk.
The vulnerability, designated as CVE-2026-59310 with a CVSS score of 9.8, is a severe directory traversal flaw that allows attackers to execute arbitrary code on affected systems. Broadcom released a patch for this issue on July 29, 2026.
German incident response firm QUIRSO has assessed with moderate confidence that the exploitation campaign targeting CVE-2026-59310 is operated by a Chinese-speaking threat actor, likely operating within the UTC+08:00 time zone. This assessment is based on several factors, including the presence of Chinese-language artifacts in attacker-created scripts, the reuse of research from Chinese security publications, the use of Chinese-language tools and management software, a victimology that excludes mainland China, and activity patterns aligning with UTC+08:00 working hours.
The exploitation campaign began five days after the public disclosure of the vulnerability and is estimated to have compromised 361 unique victim IP addresses across 47 countries. The highest concentrations of infections were reported in Germany (55), the United States (41), Turkey (38), Iran (26), and France (25).
Exploitation of CVE-2026-59309
In addition to CVE-2026-59310, attackers have also exploited CVE-2026-59309, an authentication bypass vulnerability in VMware vCenter Server. Evidence indicates that malicious activity consistent with the exploitation of CVE-2026-59309 began as early as August 1, 2026. This included the creation of an administrative account on vCenter, originating from the IP address 146.59.252[.]178, and vSphere discovery via the REST API on August 3, using User-Agent strings like “GoodMoodle-VCFleet/1.0” to masquerade as legitimate VMware-related activity.
Notably, there is no overlap between the activities exploiting CVE-2026-59309 and those targeting CVE-2026-59310 on the same system. The newly created “vcenter_admin” account was not used in subsequent phases of the attack.
Exploitation of CVE-2026-59310
The exploitation of CVE-2026-59310 involved the cron daemon logging a malformed cron file named “zz-poc59310-syslog.log.” Following this, a curl or wget command was executed to retrieve a backdoor from “5.34.177[.]38:9861,” execute it, and then remove the log file. The naming convention of the log file suggests a direct reference to the CVE identifier and indicates that it was a proof-of-concept developed after the vulnerability details became public.
The “-syslog.log” suffix mirrors the vCenter Server Appliance (vCSA) remote syslog file naming convention but appears under /etc/cron.d rather than the configured syslog output directory. This suggests that the vCSA syslog server was abused to place files in a privileged execution location.
In the broader context, this incident underscores the persistent threat posed by state-sponsored actors exploiting zero-day vulnerabilities in widely used enterprise software. Organizations must prioritize timely patching and implement robust monitoring to detect and mitigate such sophisticated attacks.