Access Denied

This page requires users to be logged in and using a specific plan to access its content.

If you believe this is an error or need help, please contact
support@cybernewscentre.com


Login or Sign Up
⭠ Back
"The United States, France, Italy amongst countries impacted by ESXiArgs ransomware BI and CISA also issued a joint alert about blocking the ransomware "
Copy Page Link
CISA
The Record
Jonathan Greig
February 8, 2023

https://www.cybernewscentre.com/plus-content/content/cisa-publishes-recovery-script-for-esxiargs-ransomware-as-florida-courts-universities-reel

You have viewed 0 of your 5 complimentary articles this month.
You have viewed all 5 of your 5 complimentary articles this month.
This content is only available to subscribers. Click here for non-subscriber content.
Sign up for free to access more articles and additional features.
Create your free account
follow this story

The Cybersecurity and Infrastructure Security Agency has published a process for recovering files for organizations affected by the ESXiArgs ransomware, which has wreaked havoc on organizations across the world since last Friday. 

On its GitHub page Tuesday evening, CISA said victims should evaluate the script before using it to try to recover access to affected files. The script is based on work by two Turkish developers who posted a step-by-step tutorial earlier this week.

The ransomware exploits a 2-year-old vulnerability affecting VMWare EXSi servers — CVE-2021-21974 — and has already encrypted files at more than 3,800 organizations across the United States, France, Italy and more. The company issued a patch in 2021. ESXi servers are used to access several operating systems through one server.

Reuters reported on Tuesday that Florida’s Supreme Court, the Georgia Institute of Technology, Rice University and several schools in Hungary and Slovakia were some of the ransomware’s victims. 

CISA specifically pointed to the work of Enes Sönmez and Ahmet Aykaç, two developers for the Turkish food retail and distribution company Yöre Group.

The script works “by reconstructing virtual machine metadata from virtual disks that were not encrypted by the malware,” CISA said.

CISA went on to warn that it “does not assume liability for damage caused by this script.”

The FBI and CISA also issued a joint alert about blocking the ransomware and responding to attacks.

European cybersecurity authorities began warning of “massive active network exploitation” on Friday. Italy’s National Cybersecurity Agency (ACN) joined France’s computer emergency response team (CERT-FR) and Finland’s Kyberturvallisuuskeskus (Cybersecurity Center) in issuing warnings over the weekend about the campaign.

References:

National Cybersecurity Agency (ACN)

General Secretariat for Defense and National Security of the Republic of France

The Cybersecurity and Infrastructure Security Agency has published a process for recovering files for organizations affected by the ESXiArgs ransomware, which has wreaked havoc on organizations across the world since last Friday. 

On its GitHub page Tuesday evening, CISA said victims should evaluate the script before using it to try to recover access to affected files. The script is based on work by two Turkish developers who posted a step-by-step tutorial earlier this week.

Get access to more articles for free.
Create your free account
More Cyber News