Maestro Payload is a malware family tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 9, 2026; most recent activity January 9, 2026.
Maestro Payload is a malware family linked to campaigns that exploit VMware ESXi hypervisor vulnerabilities. It appears as the payload within a multi-zero-day chain, underscoring the growing risk to virtualization infrastructure and the potential for persistent access within affected data centers.
Chinese-speaking threat actors conducted attacks using a VMware ESXi exploit toolkit that leveraged three zero-day vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226. The initial access…