Drv64.dll is a tool tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 7, 2026; most recent activity January 7, 2026.
Drv64.dll is a malicious driver/module identified in ESXi exploitation campaigns in the wild. It functions as a kernel-mode component used by attackers to load payloads, establish persistence, and enable privilege escalation on compromised ESXi hosts, highlighting a driver-based attack vector in hypervisor environments.
In December 2025, Chinese-speaking threat actors exploited vulnerabilities in VMware ESXi using a toolkit delivered through a compromised SonicWall VPN appliance. The toolkit included exploits for three zero-day…