The cybercrime group known as Scattered Spider is targeting VMware ESXi hypervisors primarily through social engineering tactics rather than exploiting software vulnerabilities. Their campaign focuses on gaining deep access to critical systems, allowing for data theft and ransomware deployment, especially in North American sectors like retail and transportation. #ScatteredSpider #VMwareESXi #UNC3944
Keypoints
- Scattered Spider uses social engineering to target VMware ESXi hypervisors in critical industries.
- The groupβs tactics include impersonating IT help desk staff to gain initial access.
- They leverage Active Directory and vSphere environments to pivot within networks and escalate privileges.
- The attack chain involves disk-swap techniques, SSH access, and deploying ransomware via SCP/SFTP.
- Organizations are advised to implement layered defenses such as lockdown mode, MFA, and log monitoring to mitigate these threats.
Read More: https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html