mimile
Back to feed

QUIRSO ties China-linked actor to VMware vCenter exploit, 361 IPs hit

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

QUIRSO ties China-linked actor to VMware vCenter exploit, 361 IPs hit

German incident response firm QUIRSO said it assessed with moderate confidence that a suspected China-nexus actor exploited CVE-2026-59310, a VMware vCenter flaw, compromising 361 unique victim IP addresses across 47 countries. The exploitation campaign began five days after Broadcom disclosed the flaw on July 29, 2026, and investigators also saw CVE-2026-59309 exploitation on one compromised server.

Key Facts

  • QUIRSO researchers Maike Orlikowski, Çağatay Yürekli, and Denis Szadkowski said the attribution rests on Chinese-language artifacts, reuse of a Chinese security publication, and UTC+08:00 working patterns.
  • The activity compromised 361 unique victim IP addresses across 47 countries, with Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25) most affected.
  • Broadcom released a fix for CVE-2026-59310, a directory-traversal flaw with a CVSS score of 9.8, on July 29, 2026.
  • On one vCenter Server Appliance, malicious activity consistent with CVE-2026-59309 exploitation began as early as August 1, 2026 and created an administrative account from IP address 146.59.252[.]178.
  • The newly created "vcenter_admin" account was not used in subsequent phases of the attack on that system.

Attribution Basis

QUIRSO researchers Maike Orlikowski, Çağatay Yürekli, and Denis Szadkowski said the assessment combines Chinese-language artifacts in attacker-created scripts, apparent reuse of research from a Chinese security publication, repeated use of Chinese-language tools, and activity patterns compatible with UTC+08:00 working hours. The victimology excludes mainland China, which QUIRSO also counted as a signal in its moderate-confidence assessment. The exploitation campaign began five calendar days after public disclosure of CVE-2026-59310.

CVE-2026-59310 Victim Spread

Exploitation of CVE-2026-59310 compromised 361 unique victim IP addresses across 47 countries. Germany recorded 55 infections, the United States 41, Turkey 38, Iran 26, and France 25. Broadcom fixed the directory-traversal flaw on July 29, 2026 and rated it CVSS 9.8 severity.

CVE-2026-59309 Abuse

One compromised vCenter Server Appliance showed activity consistent with CVE-2026-59309 exploitation as early as August 1, 2026. The activity created an administrative account on vCenter from IP address 146.59.252[.]178. On August 3, the actor used the vSphere REST API for discovery with User-Agent "GoodMoodle-VCFleet/1.0" to masquerade as VMware-related activity. QUIRSO found no overlap between this CVE-2026-59309 chain and the CVE-2026-59310 chain on the same system starting August 3, and the new "vcenter_admin" account was not used in later phases.

1 source

QUIRSO ties China-linked actor to VMware vCenter exploit, 361 IPs hit