{"id":4516,"date":"2023-02-14T10:41:38","date_gmt":"2023-02-14T15:41:38","guid":{"rendered":"https:\/\/lg-staging.lougcloud.com\/?p=4516"},"modified":"2025-05-05T08:19:43","modified_gmt":"2025-05-05T13:19:43","slug":"cisa-warns-organizations-to-guard-against-esxi-ransomware-attacks","status":"publish","type":"post","link":"https:\/\/lg-staging.lougcloud.com\/?p=4516","title":{"rendered":"CISA Warns Organizations to Guard against ESXi Ransomware Attacks"},"content":{"rendered":"\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-85bp3-f856194ef33e7bc72ec0d3bf98278fce\">\n.flex_column.av-85bp3-f856194ef33e7bc72ec0d3bf98278fce{\nborder-radius:0px 0px 0px 0px;\npadding:0px 0px 0px 0px;\n}\n<\/style>\n<div  class='flex_column av-85bp3-f856194ef33e7bc72ec0d3bf98278fce av_one_full  avia-builder-el-0  avia-builder-el-no-sibling  first flex_column_div av-zero-column-padding  '     ><p><br \/>\n<section  class='av_textblock_section av-k0pon615-893cfe61b16f1cf5ecc4ac5b8f5d4aed '  ><div class='avia_textblock' ><h1>CISA Warns Organizations To Guard Against ESXi Ransomware Attacks<\/h1>\n<\/div><\/section><br \/>\n<section  class='av_textblock_section av-k0pop9td-bbcbe599b29853166e54fa81e9bef78a '  ><div class='avia_textblock' ><p>A two-year-old VMware ESXi vulnerability is proving problematic for some organizations that previously failed to patch affected servers. Malicious actors are actively exploiting a corresponding ESXi bug to spread ESXiArgs ransomware. The attacks reportedly target the OpenSLP service on outdated, unpatched or out-of-service publicly accessible VMware ESXi servers to enable encrypting ESXi configuration files, thereby corrupting the servers&#8217; operations.<\/p>\n<p>The Cybersecurity &amp; Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have together issued Alert AA23-039A. The bulletin provides guidance, as well as information regarding an ESXiArgs recovery script CISA made available to assist stricken organizations in potentially recovering from ESXiArgs ransomware attacks.<\/p>\n<p>Because ESXiArgs ransomware corrupts virtual machine configuration files and (at least, initially) not flat files, in some cases impacted firms can, according to CISA, &#8220;reconstruct the encrypted configuration files based on the unencrypted flat file.&#8221; The agency&#8217;s recovery script aims to assist victims in recreating the damaged configuration files and thereby recover proper operation.<\/p>\n<p>Victims of ESXiArgs ransomware should, before executing the agency&#8217;s recovery script, review the file and its accompanying read me information before proceeding. CISA notes the recovery script does not delete encrypted configuration files but creates new ones, instead, in an effort to re-enable accessing the impacted virtual machines (VMs).<\/p>\n<p>Impacted organizations should continually monitor ESXiArgs ransomware news from credible sources for updates. New variants have reportedly arisen that encrypt additional files, making recovery efforts subsequently more difficult and complex.<\/p>\n<p>Both CISA and the FBI recommend companies with VMware ESXi servers perform the following three actions:<\/p>\n<ol>\n<li>Download and install the latest ESXi software updates<\/li>\n<li>Disable the ESXi Service Location Protocol (SLP) service<\/li>\n<li>Confirm ESXi servers are not publicly accessible from the Internet<\/li>\n<\/ol>\n<p>Within Alert AA23-039A, CISA and the FBI also present cybersecurity best practices information. The agency and bureau recommend organizations guard against ransomware infections by maintaining offline backups, regularly testing backup sets to confirm they can be restored as required, encrypting all backups and maintaining comprehensive cybersecurity response plans. Other ransomware-prevention steps the bulletin urges firms adopt include disabling or removing outdated versions of Server Message Block (SMB) protocol, implementing multifactor authentication (MFA), maintaining user education training programs, continually auditing administrative- and elevated-privilege user accounts, regularly updating antimalware software and disabling hyperlinks in incoming email messages.<\/p>\n<p>If you&#8217;re unsure your office is properly prepared against cybersecurity threats, or if you&#8217;ve having trouble confirming your VMware ESXi hypervisors are updated and properly secured, contact Louisville Geek. You can reach a Louisville Geek technology expert at 502-897-7577 or by emailing sales@lougeek.com.<\/p>\n<p>.<\/p>\n<\/div><\/section><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":2,"featured_media":4517,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-4516","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-geek-news"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CISA Warns to Guard Against ESXi Ransomware Attacks | Louisville Geek<\/title>\n<meta name=\"description\" content=\"Hackers have exploited a 2-year-old VMware vulnerability in ESXi server. Here is what you should know.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA Warns to Guard Against ESXi Ransomware Attacks | Louisville Geek\" \/>\n<meta property=\"og:description\" content=\"Hackers have exploited a 2-year-old VMware vulnerability in ESXi server. Here is what you should know.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lg-staging.lougcloud.com\/?p=4516\" \/>\n<meta property=\"og:site_name\" content=\"Louisville Geek\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-14T15:41:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-05T13:19:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/VMware.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"776\" \/>\n\t<meta property=\"og:image:height\" content=\"505\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"LouGeek Marketing\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"LouGeek Marketing\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISA Warns to Guard Against ESXi Ransomware Attacks | Louisville Geek","description":"Hackers have exploited a 2-year-old VMware vulnerability in ESXi server. Here is what you should know.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"CISA Warns to Guard Against ESXi Ransomware Attacks | Louisville Geek","og_description":"Hackers have exploited a 2-year-old VMware vulnerability in ESXi server. Here is what you should know.","og_url":"https:\/\/lg-staging.lougcloud.com\/?p=4516","og_site_name":"Louisville Geek","article_published_time":"2023-02-14T15:41:38+00:00","article_modified_time":"2025-05-05T13:19:43+00:00","og_image":[{"width":776,"height":505,"url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/VMware.jpg","type":"image\/jpeg"}],"author":"LouGeek Marketing","twitter_card":"summary_large_image","twitter_misc":{"Written by":"LouGeek Marketing","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516#article","isPartOf":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516"},"author":{"name":"LouGeek Marketing","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/person\/a381cd0bd66b806f0da449297a82ce8a"},"headline":"CISA Warns Organizations to Guard against ESXi Ransomware Attacks","datePublished":"2023-02-14T15:41:38+00:00","dateModified":"2025-05-05T13:19:43+00:00","mainEntityOfPage":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516"},"wordCount":669,"publisher":{"@id":"https:\/\/lg-staging.lougcloud.com\/#organization"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516#primaryimage"},"thumbnailUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/VMware.jpg","articleSection":["Geek News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516","url":"https:\/\/lg-staging.lougcloud.com\/?p=4516","name":"CISA Warns to Guard Against ESXi Ransomware Attacks | Louisville Geek","isPartOf":{"@id":"https:\/\/lg-staging.lougcloud.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516#primaryimage"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516#primaryimage"},"thumbnailUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/VMware.jpg","datePublished":"2023-02-14T15:41:38+00:00","dateModified":"2025-05-05T13:19:43+00:00","description":"Hackers have exploited a 2-year-old VMware vulnerability in ESXi server. Here is what you should know.","breadcrumb":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lg-staging.lougcloud.com\/?p=4516"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516#primaryimage","url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/VMware.jpg","contentUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/VMware.jpg","width":776,"height":505},{"@type":"BreadcrumbList","@id":"https:\/\/lg-staging.lougcloud.com\/?p=4516#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lg-staging.lougcloud.com\/"},{"@type":"ListItem","position":2,"name":"CISA Warns Organizations to Guard against ESXi Ransomware Attacks"}]},{"@type":"WebSite","@id":"https:\/\/lg-staging.lougcloud.com\/#website","url":"https:\/\/lg-staging.lougcloud.com\/","name":"Louisville Geek","description":"Empowering Local Businesses and National Enterprises with Comprehensive IT Services","publisher":{"@id":"https:\/\/lg-staging.lougcloud.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lg-staging.lougcloud.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/lg-staging.lougcloud.com\/#organization","name":"Louisville Geek","url":"https:\/\/lg-staging.lougcloud.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/logo\/image\/","url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2019\/10\/lougeek_full_logo-black-1.png","contentUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2019\/10\/lougeek_full_logo-black-1.png","width":1671,"height":506,"caption":"Louisville Geek"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/person\/a381cd0bd66b806f0da449297a82ce8a","name":"LouGeek Marketing","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/865f8a8b853c689f8443338c8f8d08b8e9a9f0bcab6dcd97b1cb63a5efeda3fa?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/865f8a8b853c689f8443338c8f8d08b8e9a9f0bcab6dcd97b1cb63a5efeda3fa?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/865f8a8b853c689f8443338c8f8d08b8e9a9f0bcab6dcd97b1cb63a5efeda3fa?s=96&d=mm&r=g","caption":"LouGeek Marketing"},"url":"https:\/\/lg-staging.lougcloud.com\/?author=2"}]}},"_links":{"self":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/4516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4516"}],"version-history":[{"count":3,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/4516\/revisions"}],"predecessor-version":[{"id":7953,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/4516\/revisions\/7953"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/media\/4517"}],"wp:attachment":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}