Particle.news

Download on the App Store

Scattered Spider Exploits VMware vSphere Hypervisors for Stealth Ransomware Attacks

Google’s Threat Intelligence Group warns UNC3944’s social engineering-enabled vSphere exploits can deliver stealthy ransomware within hours, leaving traditional security tools blind

Scattered Spider Launching Ransomware on Hijacked VMware Systems, Google
Image
Image

Overview

  • UNC3944 gains initial access through phone-based help-desk impersonation that breaches Active Directory credentials
  • After securing AD privileges, attackers hijack VMware vCenter Server, reboot it into single-user mode, and deploy Teleport to maintain covert hypervisor access
  • From the hypervisor layer, they pivot into ESXi hosts to steal credential databases, disable backups, and launch ransomware that evades in-guest defenses
  • The campaigns target major US retail, airline, and insurance organizations and can move from initial breach to full encryption in mere hours
  • Security experts advise shifting from endpoint detection to virtualization-focused defenses, including disabling direct ESXi shell access, encrypting VM data, isolating backups, and enforcing phishing-resistant multi-factor authentication