Skip to main content
Ransomware Group

Esxiargs

ESXiArgs is a ransomware campaign that emerged in February 2023, targeting VMware ESXi servers by exploiting the CVE-2021-21974 vulnerability. It encrypts virtual machine configuration files (.vmdk, .vmx, .vmxf, .vmsd, .vmsn, .vswp, .vmss, .nvram, .vmem) rendering VMs inaccessible. The campaign compromised thousands of unpatched servers globally, primarily affecting European organizations. A decryptor was later released by CISA and FBI.

Known victims0

Threat Level

LOW

0

Check If You’re Affected

Search our database to see if your organization appears in Esxiargs’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request