-

CyberCube Identifies Potential Targets in VMware Ransomware Campaign

SAN FRANCISCO--(BUSINESS WIRE)--CyberCube, the market leader in cyber risk analytics, has identified companies at risk of attack in a new ransomware campaign impacting thousands of businesses globally.

The automated ransomware campaign called ESXiArgs is targeting outdated VMware ESXi servers globally. Starting on Feb 9, 2023, the cybersecurity community reported threat actors successfully improving their attacks. The campaign encrypts configuration files on vulnerable ESXi servers, potentially rendering clients’ virtual machines (VMs) unusable. Internet-wide scans within days after the first reports surfaced showed a rapid infection rate with over 2,000 servers infected.

According to the research “CyberCube Briefing: Ransomware Risks & VMware Servers”, up to 70,000 ESXi hypervisors globally could become vulnerable. CyberCube has analyzed companies in its Industry Exposure Database (IED) to identify organizations running VMware ESXi hypervisors that could be vulnerable to the ESXiArgs ransomware.

William Altman, CyberCube’s Cyber Threat Intelligence Principal, said: “Large US-based insureds operating in banking, education, manufacturing, non-profit, aviation, and agriculture are at higher risk of being attacked by threat actors leveraging vulnerabilities in ESXi hypervisors compared to insureds operating in other industries.

“Large insureds ($1 billion-plus revenue) are at greater risk than medium, small, or micro-sized insureds. Large-sized companies are more likely to require the use of hypervisors and virtual machines as the foundation for the large-scale deployment of cloud computing and cloud storage resources.”

Yvette Essen, CyberCube’s Head of Content, Communications & Creative, said: “The majority of impacted ESXi servers are in France and Germany. Cybersecurity agencies in other countries, including Singapore, have also raised alarms. At least a dozen universities have been reported to be impacted, including the Georgia Institute of Technology in Atlanta, Rice University in Houston, and institutions of higher learning in Hungary and Slovakia. Florida’s Supreme Court has also stated that it was impacted by ESXiArgs ransomware.”

CyberCube has modeled a large-scale ransomware attack as part of Portfolio Manager, a scenario-based data-driven model that enables risk professionals to develop insights for their senior leadership and teams. It also allows stress testing of portfolios of insurance risk so that loss drivers and areas of accumulation risk can be identified.

About CyberCube

CyberCube delivers the world’s leading cyber risk analytics for the insurance industry. With best-in-class data access and advanced multi-disciplinary analytics, the company’s cloud-based platform helps insurance organizations quantify cyber risk to facilitate placing insurance, underwriting cyber risk and managing cyber risk aggregation. CyberCube’s enterprise intelligence layer provides insights on millions of companies globally and includes modeling on thousands of points of technology failure.

Contacts

Yvette Essen
Head of Content, Communications & Creative
yvettee@cybcube.com

CyberCube


Release Versions

Contacts

Yvette Essen
Head of Content, Communications & Creative
yvettee@cybcube.com

More News From CyberCube

New CyberCube Report Highlights Global Ransomware Trends and Methods to Navigate Leaner Conditions

LONDON--(BUSINESS WIRE)--Ransomware is growing beyond traditional hotspots and in emerging economies, including Latin America, Africa, the Middle East, and Asia, according to CyberCube’s latest research. The report, titled “Applying Analytics and Threat Intelligence to Grow in a Soft Market”, states these trends underscore ransomware’s shift beyond traditional hotspots and toward regions undergoing rapid digitalization, uneven defense, and growing strategic importance. CyberCube’s H2 2025 Globa...

CyberCube Reveals Insurance Loss Estimate for AWS “Amazonk” Outage

SAN FRANCISCO--(BUSINESS WIRE)--CyberCube, the leading cyber risk analytics provider, has released a preliminary loss estimate for the Amazon Web Services (AWS) outage ranging from $38 million to $581 million. The event, which CyberCube is nicknaming “Amazonk”, is expected to have a loss ratio impact for cyber insurers in the low- to mid-single digits, in keeping with CyberCube’s view that this event presents the potential for only moderate insurance impact. Although the event could play out in...

CyberCube Raises More Than $180MM from New Cornerstone Investor Spectrum Equity

SAN FRANCISCO--(BUSINESS WIRE)--CyberCube, a leading cyber risk modeling and analytics business, today announced an investment of more than $180MM by Spectrum Equity, subject to customary regulatory approvals. With this investment, Spectrum Equity will join existing investors ForgePoint Capital, Hudson Structured Capital Management (Bermuda) Ltd, and MTech Capital, as a cornerstone institutional investor, supporting the company's long-term growth and innovation. CyberCube is the analytics engin...
Back to Newsroom