Akira Group Targets Hyper-V and VMware ESXi with Ransomware Exploiting Vulnerabilities
Hypervisors have emerged as a significant target for ransomware groups, according to recent data from Huntress. These attacks have intensified towards the end of 2025.
Hypervisors have emerged as a significant target for ransomware groups, according to recent data from Huntress. These attacks have intensified towards the end of 2025.
Hypervisors such as VMware ESXi and Microsoft Hyper-V are integral to enterprise virtual machines (VMs), yet they often lack robust security measures. This makes them a strategic target for attackers.
Huntress Security Operations Center (SOC) data indicates a substantial increase in ransomware incidents involving hypervisors, rising from 3% in early 2025 to 25% in the latter half of the year. These breaches allow attackers to bypass traditional endpoint detection and response (EDR) tools.
Attackers typically infiltrate networks using compromised credentials or unpatched VPNs, then move to the hypervisor management plane. Rather than deploying custom malware, they utilize existing tools such as OpenSSL for encryption.
Hypervisors have emerged as a significant target for ransomware groups, according to recent data from Huntress.
A notable vulnerability, CVE-2024-37085, allows attackers with sufficient Active Directory permissions to assume control of ESXi hosts, enabling rapid encryption of VMs.
Securitizing hypervisors demands a comprehensive defense strategy:
Isolate Management Networks: Hypervisors should be segregated from the corporate network using a dedicated VLAN and access enforced through secure jump boxes. Strict Identity Management: Use dedicated local accounts for ESXi management and implement Multi-Factor Authentication (MFA) for all management interfaces. Runtime Hardening: Enable features such as VMkernel.Boot.execInstalledOnly=TRUE to restrict execution to signed binaries only. Immutable Backups: Adopt the "3-2-1" backup rule and ensure backups are immutable and isolated from Active Directory.
As organizations strengthen endpoint defenses, attackers increasingly target hypervisors. Treating hypervisors as high-value assets, with appropriate patching and monitoring, can mitigate potential threats and prevent system-wide breaches.
Based on reporting by GBHackers.
