BR +55 11 3069 3925 | USA +1 469 620 7643

CISA and FBI Release ESXiArgs Ransomware Recovery Script

by | Feb 15, 2023 | BLOG | 0 comments

The US Cyber Security and Infrastructure Agency (CISA) and the Federal Bureau of Investigation (FBI) released this week a recovery guide for the ESXiArgs ransomware, which has harmed thousands of companies globally.

This was because malicious attackers were allegedly taking advantage of known vulnerabilities in unpatched, out-of-service or outdated versions of VMware ESXi software. Through these “loopholes” they would be deploying ESXiArgs ransomware on ESX servers, rendering these devices unusable.

The recovery tool can be found at this link and has been used by numerous corporations, who managed to recover encrypted items without paying a ransom to attackers.

However, CISA warns that to use this resource, it is essential to understand how it works. In this sense, companies harmed by ESXiArgs should evaluate the recommendations present in the README file, which comes with the script.

The number of servers infected by ESXiArgs in several countries has already exceeded 3 thousand. According to the victims, in order to decrypt the data, the hackers requested about 2 Bitcoins, which is equivalent to approximately US$ 22,800 (as of the present moment).

In addition, malicious attackers would have demanded payment of the ransom within three days, as a condition for not disclosing the organizations’ sensitive data.

As per Rapid 7, ESXiArgs attempted to shut down virtual machines by killing a process in the virtual machine’s kernel that handles I/O commands, however, in some cases it was unsuccessful as organizations were able to recover their data.

The recovery script developed by CISA in conjunction with the FBI is based on the work of researchers Enes Sonmez and Ahmet Aykac, and shows how victims can rebuild virtual machine metadata from disks that the malware was unable to encrypt.

In practice, the function of the script is to create new configuration files that allow access to the VMs and not delete encrypted files. However, CISA makes no guarantees that the script is secure.

VMware recommends that companies implement the patch released in 2021 for the vulnerability exploited by ESXiArgs. Organizations that do not fix the flaw should temporarily disable the ESXi Service Location Protocol (SLP) or still keep port 427 disabled.

Are you enjoying this post? Join our Newsletter!

Newsletter Blog EN

2 + 6 =

We will send newsletters and promotional emails. By entering my data, I agree to the Privacy Policy and the Terms of Use.

senhasegura wins CyberSecured 2022 award as best PAM solution in the USA

Written by Priscilla Silva SÃO PAULO, February 28 of 2023 - The 2022 edition of the CyberSecured awards, promoted by Security Today magazine, a brand of 1105 Media's Infrastructure Solutions Group, elected senhasegura as the winner in the Privileged Access Management...

BYOD Security: Complete Guide

The Covid-19 pandemic has accelerated the digital transformation process and forced many organizations to operate remotely. In many cases, employees started to use their personal devices to access corporate data and resources. This practice is known as Bring Your Own...

How Does PAM Help Protect Remote Access?

With the imposition of social distancing caused by the Covid-19 pandemic, most companies began to migrate to remote work, adopting solutions such as cloud computing. According to Forrester, more than 50% of IT leaders have revealed the need to adapt to this reality,...

senhasegura introduces the “Jiu-JitCISO” concept to show the power of Brazilian cybersecurity

Written by Priscilla Silva São Paulo, January 13, 2023 - "Like Jiu-Jitsu senhasegura is about self-defense. Every company must know how to protect itself and its clients". This is the aim based on the philosophy of the Japanese martial art, but made popular and...

2023 KuppingerCole Leadership Compass: senhasegura is a PAM leader for the second year in a row

Written by Ina Schindler and Priscilla Silva São Paulo, January 30, 2023 - The Privileged Access Management (PAM) solution senhasegura achieves a top position in the "Leadership Compass 2023". The report is produced by the renowned IT analyst firm KuppingerCole to...