Related Threat Clusters
-
China-linked Cybercriminals Exploit VMware ESXi Vulnerabilities
Chinese-linked cybercriminals utilized a VMware ESXi hypervisor escape kit to target the ESXi hypervisor. Researchers from Huntress reported that the toolkit was in development as early as February 2024 and was used in…
1 article · Updated January 9, 2026 -
Chinese Cybercriminals Exploit ESXi Zero-Days Before Public Disclosure
Chinese-linked cybercriminals utilized a VMware ESXi hypervisor escape toolkit over a year prior to the public disclosure of the vulnerabilities. Researchers at Huntress identified an intrusion in December 2025,…
1 article · Updated January 9, 2026 -
Chinese-speaking actors exploit VMware ESXi zero-days via SonicWall VPN breach
Chinese-speaking threat actors conducted attacks using a VMware ESXi exploit toolkit that leveraged three zero-day vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226. The initial access…
1 article · Updated January 9, 2026 -
Chinese-Speaking Threat Actors Exploit VMware ESXi via Compromised SonicWall VPN
In December 2025, Chinese-speaking threat actors exploited vulnerabilities in VMware ESXi using a toolkit delivered through a compromised SonicWall VPN appliance. The toolkit included exploits for three zero-day…
2 articles · Updated January 8, 2026 -
CISA Confirms Active Exploitation of VMware ESXi CVE-2025-22225
CISA has confirmed the active exploitation of a critical vulnerability in VMware ESXi, tracked as CVE-2025-22225. This zero-day flaw allows attackers to escape security sandboxes and is currently being used in…
7 articles · Updated February 5, 2026
Recent Intelligence Reports
- CISA: Ransomware intrusions exploiting VMware ESXi bug ongoing — Scworld · February 6, 2026
- CISA confirms exploitation of VMware ESXi flaw by ransomware attackers — Feeds2.Feedburner · February 5, 2026
- CISA Confirms VMware ESXi 0 — Gbhackers · February 5, 2026
- CISA Warns of VMware ESXi 0 — Cybersecuritynews · February 5, 2026
- CVE-2025 — Securityaffairs.Co · February 4, 2026
- CISA: VMware ESXi flaw now exploited in ransomware attacks — Bleepingcomputer · February 4, 2026
- Trio of VMware ESXi zero-days chained long before disclosure — Scworld · January 9, 2026
- China crew abused ESXi zero-days a year before disclosure — Theregister · January 9, 2026