esxiargs logo

esxiargs

1 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
ESXiArgs is a ransomware strain first observed in initial infections as early as October 2022, with a widespread campaign launching around February 2023. The ransomware specifically targets VMware ESXi hypervisors, encrypting virtual machine data and disrupting virtualized environments by operating at the hypervisor level rather than individual endpoints. Its primary motivation is financial gain through ransom payments for the decryption of affected systems. A distinctive characteristic is its appending of a ".args" extension to encrypted files, containing metadata likely for decryption. The ransomware evolved in February 2023 with a modified encryption method, and its code is suspected to be based on the leaked Babuk ransomware source.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

BelgiumCanadaChinaGermanyFinlandFranceUnited KingdomItalyKorea, Republic ofNetherlands

Sectores objetivo (SOCRadar)

MiningEnergy & Utilities ManufacturingRetailInformation ServicesFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social Assistance

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com