Breaking
SecurityDeveloping Story

Ransomware in VMware Attack Looks Like a Distraction

Researchers say a suspected China-nexus APT used a VMware flaw to deploy ransomware as a smoke screen.

··1 hour ago·7 min read
Green computer code text scrolling on a dark screen during a software installation
Photo by Jake Walker on Unsplash

This week in cybersecurity, the costliest attacks weren't the flashiest. Instead of novel zero-days or exotic exploits, defenders faced a wave of incidents that leaned on exposed services, unpatched bugs, and browser sessions as attack paths. One theme stood out: ransomware, the traditional endgame, may be losing its status as the final objective.

In at least one high-profile case, a suspected China-linked advanced persistent threat (APT) group exploited a critical VMware vCenter vulnerability and deployed Babuk-derived ransomware. But researchers analyzing the intrusion believe the ransomware was not the point. It was a cover-up.

A Critical VMware Flaw Under Attack

The flaw is CVE-2026-59310, a directory-traversal vulnerability in VMware vCenter server with a CVSS score of 9.8. It allows a malicious actor to execute arbitrary code. The bug was patched recently, but not before at least one organization was compromised.

According to security firm QUIRSO, which investigated the incident, the attackers exploited the vulnerability and, in at least one compromised instance, deployed a backdoor and a reverse SSH binary. The attack ultimately led to the deployment of Babuk-derived ransomware. But QUIRSO's analysis suggests the ransomware was a smokescreen, not the goal.

"Based on the case we investigated, however, we do not believe ransomware was necessarily the primary objective," QUIRSO said. "To us, its deployment looks more like a smoke screen intended to distract from the underlying intrusion and, importantly, hinder subsequent forensic analysis by encrypting evidence. We therefore see the ransomware activity in this case as potentially serving the broader intrusion rather than being its ultimate objective."

— QUIRSO, security research firm

macOS Flaw Drops Crypto Miners

Meanwhile, a critical authentication flaw in Apple macOS was exploited in the wild to deploy a cryptocurrency miner. The vulnerability, CVE-2026-65400 (CVSS 9.8), affects the Screen Sharing component and could allow an attacker already on the network to authenticate to the built-in remote desktop service without valid credentials. Apple addressed it in emergency updates for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 earlier this month.

The Netherlands National Cyber Security Center (NCSC-NL) reported active abuse across multiple systems where port 5900 was exposed to the internet. In all cases, the attacker gained root access and placed a Monero crypto miner.

Lazarus Group Exploits Windows 0-Day

North Korea's Lazarus Group was attributed to the zero-day exploitation of a Windows privilege escalation flaw, CVE-2026-68820 (CVSS 7.0), affecting the Windows Ancillary Function Driver for WinSock ("AFD.sys"). The bug was patched in Microsoft's August 2026 Patch Tuesday updates.

The attacks, part of Operation Dream Job, delivered a never-before-seen backdoor called Troy, alongside a previously known tool called ForestTiger. Targets included defense and aerospace companies in France, Germany, Brazil, and India.

GeoServer SQL Injection Exploited Quickly

GeoServer released patches for a critical SQL injection vulnerability that can lead to remote code execution. The issue, which has yet to be assigned a CVE identifier, was fixed in versions 3.0.1, 2.28.5, and 2.27.6. According to watchTowr, the flaw saw active exploitation within hours of public disclosure, with hundreds of attempts originating from a small pool of IP addresses.

GeoServer project maintainers told The Hacker News that the flaw was responsibly disclosed and was scheduled to be addressed in their regular release cycle, but details became public last week.

Browser Sessions as Attack Paths

Two separate pieces of research highlighted how browser sessions are becoming a prime target. Amnesia Stealer, a newly discovered macOS stealer, targets users via ClickFix attacks. It steals data from 16 Chromium-based browsers and other sensitive information, including passwords, cryptocurrency wallets, Apple Notes, documents, and iCloud Keychain data. It also includes a streaming module that allows the attacker to interactively control the victim's web browser.

The malware copies the victim's Chromium profile, including its authentication state, and loads it into a headless browser on the infected system. This gives the operator access to authenticated sessions. The streaming module duplicates user profiles in browsers like Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, and Brave, and establishes a WebSocket channel to the operator's relay, receiving commands such as navigation and mouse clicks. The remote-control component uses the Chrome DevTools Protocol (CDP).

"The operator receives a live screencast of the session at around 3fps and can drive it with a full input set: keyboard, mouse, scroll, navigation and tab management," Jamf said. "In effect, the remote_stream command turns an infected host into a live, operator-driven browser running the victim's authenticated sessions, which is a materially different level of access from file collection."

Amnesia Stealer is the first documented macOS malware to combine a cloned Chromium profile with CDP-based, real-time remote control.

Separately, SpecterOps detailed a post-exploitation technique that enables CDP inside a live Google Chrome or Microsoft Edge process on Windows. The goal is to steal cookies, saved data, and authenticated browser sessions, provided the attacker already has code execution permissions. "Cookie protections like ABE and device-bound session cookies make it harder to steal and replay session material, but they do not remove the value of an authenticated browser to adversaries," SpecterOps said. "Once CDP is enabled inside a Chromium browser, an operator can use the browser context to sidestep those replay protections, access authenticated applications, and collect saved data."

AI Assistants Under Attack

A new attack technique called GhostSplice targets AI coding assistants. It sidesteps guardrails by parsing malicious requests split and hidden across different channels, such as an MCP tool description, a tool result, and a sampling message. Each request is benign on its own, so the assistant processes it without refusal.

The attack relies on the fact that all tool channels, files, and chat content flow into one block of the assistant's memory. There is no marking to separate content by source, so the assistant reads it all as a single page. This is a case of cross-channel trust fragmentation: the attacker embeds a harmless piece in each source, and the assistant stitches them back into one instruction.

More Flaws and Fast Patches

VulnCheck disclosed CVE-2026-14863, a high-severity OS command injection flaw in FileRun with a CVSS score of 8.7. The bug allows remote code execution. Security researcher Valentin Lobstein explained that FileRun's thumbnail extractors build shell commands by pasting the uploaded file path into a double-quoted string and handing it to exec(). The filename sanitizer lets $() through, so a file named $(payload).mp4 runs its payload when a thumbnail is generated. The issue affects versions up to 2026.2.0 and was fixed in 2026.2.1.

ThreatLocker disclosed a ClickFix attack that used embedded scripts, steganographic payload extraction, and obfuscation to deploy an advanced iteration of ACR stealer and a secondary payload called GhostPipe. The attack started with a fake CAPTCHA on a compromised domain, leading to a PowerShell command that downloads an MP3 file, which is then executed using MSHTA to launch a VBScript. That VBScript runs intermediate payloads to gather system information and extract a PowerShell script from a remotely hosted JPG file. The script serves as an in-memory module shellcode launcher to deploy ACR Stealer. The malware also contacts a C2 server to fetch secondary payloads, including GhostPipe.

A Week of Widespread Exploitation

The list of trending CVEs this week is long, including critical flaws in Microsoft Windows, SAP Commerce Cloud, Adobe, Cisco, Zoom, Apple, ClamAV, OpenCart, SonicWall, Fortinet, WordPress, and more. The gap between patch and exploit is shrinking fast.

  • CVE-2026-59310 (VMware vCenter) – CVSS 9.8, exploited by suspected China-nexus APT.
  • CVE-2026-65400 (Apple macOS) – CVSS 9.8, exploited to drop Monero miner.
  • CVE-2026-68820 (Microsoft Windows) – CVSS 7.0, exploited by Lazarus Group as zero-day.
  • CVE-2026-14863 (FileRun) – CVSS 8.7, command injection leading to RCE.
  • GeoServer SQL injection – No CVE yet, but exploited within hours of disclosure.
  • Amnesia Stealer – New macOS malware combining cloned Chromium profile and CDP remote control.

Why This Matters

The VMware case, if QUIRSO's assessment holds, suggests that ransomware is no longer the sole endgame for some sophisticated attackers. It can be a cleanup tool, a way to destroy evidence and misdirect incident responders. That complicates the standard response playbook: if you treat every ransomware event as a simple extortion attempt, you might miss the underlying intrusion that was the real objective.

Similarly, the growing focus on browser sessions — both by malware like Amnesia Stealer and by post-exploitation frameworks from groups like SpecterOps — signals that authentication is the new perimeter. Attackers are betting that session data is more valuable than files, and they're finding ways to bypass protections like device-bound cookies.

For defenders, the lesson is to patch aggressively, but also to assume that a single alert might be a distraction. Look for the quieter signs of intrusion — backdoors, reverse shells, unusual outbound connections — even when ransomware is screaming for attention.

#vmware#ransomware#apt#macos#windows#browser security

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories