China-Nexus Actor Exploits Critical VMware vCenter Vulnerability

A suspected China-nexus threat actor is actively exploiting the VMware vCenter vulnerability CVE-2026-59310. The critical flaw enables remote code execution with root privileges and has been linked to at least 361 compromised IP addresses across 47 countries.Available evidence indicates with moderate confidence that a Chinese-speaking threat actor is responsible. Researchers identified Chinese-language content in scripts and the use of Chinese-language tools. They found no identified victims in mainland China, while observed activity also aligned with UTC+08:00 working hours.VMware vCenter vulnerability under active exploitationThe threat actor installed a custom Linux backdoor, reverse SSH tools, SSH keys and JSP web shells. It also created cron jobs labelled as VMware services. In addition, the actor attempted to obtain VMware Directory Service credentials and created new vCenter administrative accounts.After compromising vCenter, the actor accessed connected ESXi infrastructure. It then deployed additional remote-access tools and privileged accounts. In one case, it deployed Babuk-derived ransomware that encrypted ESXi-hosted files with the “.babyk” extension.However, researchers have not identified ransomware across the wider campaign. As a result, the actor’s main objective remains unclear. The activity could indicate disruption, persistent access, or both.What organisations should look forThe extensive persistence suggests that the suspected China-nexus actor may seek long-term access to virtualised environments. Organisations should therefore review affected environments for signs of persistence, credential access and unauthorised accounts.Security teams should also investigate activity involving connected ESXi hosts. Where affected versions are in use, organisations should prioritise patching and review the official Broadcom advisory for CVE-2026-59310.Why the VMware vCenter vulnerability mattersvCenter is a high-value target because it provides centralised control over virtual infrastructure supporting multiple ESXi hosts and virtual machines. Successful exploitation can therefore allow an attacker to move beyond one compromised server and maintain privileged access across a wider virtualised environment.This week’s Weekly Intelligence Summary also covers phishing-as-a-service activity, Microsoft vulnerabilities and a claimed Azure compromise. Download the full report for the complete intelligence overview.Orpheus provides cyber threat intelligence to help organisations understand which threats are most relevant to their environment and where action should be prioritised.

Download the full report

VMware vCenter vulnerability CVE-2026-59310 Weekly Intelligence Summary
Scroll to Top

Become a Partner

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Please complete the form below and we’ll be in touch shortly.