https://cybernews.com/news/global-ransomware-attack-targets-vmware-servers/
Attackers are exploiting a known vulnerability to target hundreds of servers in France, the USA, Germany, Finland, Italy, and other countries.
France’s Computer Emergency Response Team (CERT-FR) was among the first to notice the massive ransomware campaign, as hundreds of affected VMware ESXi servers were using French cloud service provider OVHcloud.
“[…] these campaigns seem to exploit the CVE-2021-21974 vulnerability, which has been patched since February 23, 2021. This vulnerability affects the Service Location Protocol (SLP) service and allows an attacker to execute arbitrary code remotely,” CERT-FR said on February 3.
According to a ransomware note obtained by Darkfeed, a deep web monitoring feed, the attackers don’t direct victims to a ransomware leak site, as is a custom in the cyber underworld, instead providing the address to an encrypted messaging service…
..Security researchers scramble for fixes to decrypt the thousands of irresponsive services worldwide. According to cybersecurity expert Matthiey Gari, the attackers only encrypt the config files, allowing defenders to mitigate the damage somewhat…