ESXiArgs
- First seen
- 2023-02-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-20 09:55:34
- Profile updated
- 2026-07-07 14:24:35
Targeted industries: technology-and-telecommunications
Context
ESXiArgs is ransomware specifically designed to target ESXi servers. It exploits vulnerabilities in virtualization environments to encrypt data and demand ransom payment for decryption.
Detection coverage
- 4 YARA rules
Detection rules
- SECUINFRA_RANSOM_Esxiargs_Ransomware_Encryptor_Feb23 (yara-rule)
- SECUINFRA_RANSOM_Esxiargs_Ransomware_Python_Feb23 (yara-rule)
- SECUINFRA_RANSOM_Esxiargs_Ransomware_Bash_Feb23 (yara-rule)
- SIGNATURE_BASE_SUSP_Esxiargs_Endpoint_Conf_Aug23 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Esxi Args (report)
- blog.ovhcloud.com — Ransomware Targeting Vmware Esxi (report)
- youtube.com — Watch (report)
- secuinfra.com — Hide Your Hypervisor Analysis Of Esxiargs Ransomware (report)
- bleepingcomputer.com — Massive Esxiargs Ransomware Attack Targets Vmware Esxi Servers Worldwide (report)