China-linked Cybercriminals Exploit VMware ESXi Zero-Days Before Disclosure
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Researchers at Huntress revealed that cybercriminals linked to China had developed a VMware ESXi hypervisor escape toolkit over a year before the vulnerabilities were disclosed in March 2025. The attack was identified in December 2025 and initiated through a compromised SonicWall VPN appliance, allowing attackers to gain access to a Domain Admin account and pivot across the network.
The attackers utilized multiple flaws to escape a guest virtual machine (VM) and execute code on the underlying ESXi hypervisor. This is particularly concerning as VM escape vulnerabilities undermine the fundamental isolation that virtualization technology provides, allowing malicious actors to breach the hypervisor.
Huntress’s analysis indicated that the toolkit was designed to target a wide range of ESXi versions, with over 150 builds potentially affected. The code contained simplified Chinese strings and timestamps showing development well before VMware acknowledged the vulnerabilities, indicating a high level of sophistication and planning.
The vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, were classified as critical and high-severity by VMware, which warned that exploitation had occurred in the wild. This suggests that organizations were at risk even before they were aware of the vulnerabilities.
This incident reflects a broader trend of Chinese-linked attackers quietly exploiting zero-day vulnerabilities in widely used enterprise software, as seen in previous campaigns like Volt Typhoon. Such tactics allow attackers to remain undetected within networks for extended periods, posing significant risks to organizational security.
Understanding the Risks
Organizations using VMware ESXi should be particularly vigilant about the security of their hypervisors. The exploitation of these vulnerabilities underscores the importance of timely patching and monitoring for unusual activity within their networks.
As cyber threats continue to evolve, it is crucial for IT teams to stay informed about potential vulnerabilities and to implement robust security measures to protect against sophisticated attacks.
Key Takeaways
- Regularly update and patch VMware ESXi hosts to mitigate known vulnerabilities.
- Monitor network activity for signs of unauthorized access or unusual behavior.
- Implement strong access controls and limit the use of Domain Admin accounts.
- Conduct regular security audits of VPN appliances and other entry points.
- Educate staff about the risks of cyber threats and the importance of security hygiene.
Key Terms & Concepts
- VMware ESXi: VMware ESXi is a hypervisor that allows multiple virtual machines to run on a single physical server.
- VM escape: VM escape refers to a security vulnerability that allows an attacker to break out of a virtual machine and access the host system.
- CVE: CVE stands for Common Vulnerabilities and Exposures, a system for identifying and cataloging publicly known cybersecurity vulnerabilities.
- SonicWall VPN: SonicWall VPN is a virtual private network solution that provides secure remote access to an organization’s network.
- Chinese-linked cybercriminals: Chinese-linked cybercriminals refer to threat actors believed to be operating from China, often involved in sophisticated cyberattacks.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.