Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
A suspected Chinese-speaking APT is mass-exploiting a critical Broadcom VMware vCenter directory-traversal flaw (CVE-2026-59310, CVSS 9.8) to plant backdoors and stage ransomware across 361 victims in 47 countries.
Intelligence analysis by Llama

QUIRSO attributes exploitation of a 9.8-rated VMware vCenter bug to a China-nexus APT working in UTC+08:00. Five days after disclosure, 361 IPs in 47 countries were compromised, with Germany, the U.S., Turkey, Iran, and France hit hardest.
Hackers found a giant unlocked door in a popular computer-management program called VMware vCenter, and within days they used it to sneak into hundreds of companies around the world. Experts think the intruders speak Chinese, work during Beijing office hours, and left behind tools that let them lock up computers and demand money to unlock them.
Analysis
The 9.8-Severity Directory Traversal Flaw
CVE-2026-59310 is a directory-traversal vulnerability in VMware vCenter Server that Broadcom patched on July 29, 2026. With a CVSS score of 9.8, the bug sits in software that controls entire virtualized estates, meaning a single successful exploit can hand an attacker the keys to every workload running on a host. QUIRSO's reconstruction of the attack shows the actor abusing the vCSA syslog functionality to drop a malformed cron file, named "zz-poc59310-syslog.log," into /etc/cron.d. The suffix mirrors the legitimate vCenter remote syslog naming convention, an operational detail that suggests the attacker studied Broadcom's own file layout to hide in plain sight. From there, a curl or wget command retrieved a backdoor from 5.34.177[.]38:9861, ran it, and scrubbed the log file, a tight, automated kill chain suited to sweeping the internet rather than targeting a single victim.
QUIRSO's UTC+08:00 Working Hours Signal
Attribution in cases like this rests on converging weak signals rather than a smoking gun, and QUIRSO's analysts — Maike Orlikowski, Çağatay Yürekli, and Denis Szadkowski — laid out five reinforcing indicators. They cited Chinese-language artifacts in attacker scripts, apparent reuse of a Chinese security publication, repeated use of Chinese-language management tools, victimology that pointedly excluded mainland China, and activity patterns consistent with a UTC+08:00 workday. The combination is the kind of mosaic that lets researchers say "moderate confidence" rather than "confirmed," but it is also the profile of a state-aligned intelligence operation, not a financially motivated crew. The deployment of Babuk-derived ransomware on top of the backdoor access fits a familiar dual-mandate pattern: collect intelligence quietly, then monetize or weaponize on demand.
361 Victims Across 47 Countries
The campaign's scale is what turns a serious vulnerability into a sector-wide event. QUIRSO estimated 361 unique victim IP addresses across 47 countries were compromised, with infections concentrated in Germany (55), the United States (41), Turkey (38), Iran (26), and France (25). Notably, the analysis also turned up a parallel exploitation chain on one vCenter appliance targeting CVE-2026-59309, an authentication-bypass flaw, with an administrative account "vcenter_admin" created from 146.59.252[.]178 on August 1. The implants themselves — a WebSocket-based "linuxFile" backdoor XOR-obfuscating its C2 address, plus a reverse-SSH binary exposed by an AList directory listing on 5.34.176[.]100:5244 — show an actor that is technically capable but has also made at least one operational security slip. That misstep may be the only reason defenders are reading the playbook now rather than after the ransomware detonated.
Key points
- CVE-2026-59310 is a 9.8-rated directory-traversal flaw in Broadcom VMware vCenter Server, patched on July 29, 2026
- QUIRSO attributes mass exploitation to a suspected China-nexus APT operating in the UTC+08:00 time zone, with moderate confidence
- The campaign is estimated to have compromised 361 unique victim IP addresses across 47 countries, led by Germany, the U.S., Turkey, Iran, and France
- Attackers abused the vCSA syslog path to drop a cron job that fetched a WebSocket-based 'linuxFile' backdoor and a reverse-SSH binary, enabling persistence and remote command execution
- One compromised appliance was also hit via CVE-2026-59309, an authentication-bypass bug, with a 'vcenter_admin' account created from 146.59.252[.]178
- The actor is described as deploying Babuk-derived ransomware on top of its intelligence-gathering implants, fitting a dual-mandate state-aligned profile
Broadcom shipped a fix on July 29, 2026, before the mass-exploitation wave crested, giving defenders a defensible patch to apply. QUIRSO's detailed forensic write-up also provides network indicators, file names, and TTPs that organizations and other vendors can use to hunt for and evict the actor before ransomware is detonated.
The five-day gap between disclosure and live exploitation shows the window for unpatched vCenter instances has effectively closed, and the actor's reverse-SSH and systemd persistence mechanisms make clean-up non-trivial. With 361 already compromised and victimology spanning critical infrastructure, follow-on ransomware deployment or intelligence collection could continue for months even as patches roll out.



