What happened
Google's threat intelligence team published detail in July 2025 on how UNC3944, also known as Scattered Spider, was targeting VMware vSphere and ESXi environments at US retail, airline, transportation and insurance organisations. The group did not exploit a software vulnerability; it phoned IT service desks, impersonated employees to obtain credential and MFA resets, and escalated to hypervisor administration before encrypting virtual machines from the ESXi layer.
How the deception worked
Operators researched a target employee using LinkedIn and leaked HR data, then called the service desk claiming to be that person and asking for an Active Directory password reset. Fluent English, personal details and calm insistence carried the call. With a foothold they identified vSphere administrators and called the help desk again to reset those higher-privilege accounts, sometimes adding push-notification pressure. Reaching vCenter let them enable SSH on ESXi hosts, reset root passwords, and detach and copy the domain controller disk to extract credentials. Encrypting from the hypervisor bypassed in-guest endpoint protection entirely.
The control that would have caught it· our reading, not a claim from the sources
Service desks must identity-proof callers before resetting credentials for privileged accounts, and vSphere administration should require phishing-resistant MFA with execInstalledOnly and locked-down SSH on ESXi.
Sources (2)
- Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. InfrastructureThe Hacker News·thehackernews.comOpen ↗
- Scattered Spider targets VMware ESXi using social engineeringSecurity Affairs·securityaffairs.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.