ESXiArgs

First seen
2023-02-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-20 09:55:34
Profile updated
2026-07-07 14:24:35

Targeted industries: technology-and-telecommunications

Context

ESXiArgs is ransomware specifically designed to target ESXi servers. It exploits vulnerabilities in virtualization environments to encrypt data and demand ransom payment for decryption.

Detection coverage

  • 4 YARA rules

Detection rules

  • SECUINFRA_RANSOM_Esxiargs_Ransomware_Encryptor_Feb23 (yara-rule)
  • SECUINFRA_RANSOM_Esxiargs_Ransomware_Python_Feb23 (yara-rule)
  • SECUINFRA_RANSOM_Esxiargs_Ransomware_Bash_Feb23 (yara-rule)
  • SIGNATURE_BASE_SUSP_Esxiargs_Endpoint_Conf_Aug23 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Esxi Args (report)
  • blog.ovhcloud.com — Ransomware Targeting Vmware Esxi (report)
  • youtube.com — Watch (report)
  • secuinfra.com — Hide Your Hypervisor Analysis Of Esxiargs Ransomware (report)
  • bleepingcomputer.com — Massive Esxiargs Ransomware Attack Targets Vmware Esxi Servers Worldwide (report)

External references