Security1 publisher3 min readPublished
A vCenter bug patched on July 29 is already a ransomware chain, not a ticket
QUIRSO says a suspected China-nexus actor turned CVE-2026-59310 into a backdoor, a reverse SSH binary and Babuk-derived ransomware, with 361 victim IPs across 47 countries.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- CVE-2026-59310 is a directory-traversal vulnerability in VMware vCenter Server with a CVSS score of 9.8 that could be weaponized to execute arbitrary code; Broadcom released a fix on July 29, 2026.
- In at least one compromised instance, exploitation of CVE-2026-59310 led to deployment of a backdoor and a reverse SSH binary, ultimately leading to the deployment of Babuk-derived ransomware.
- The activity is estimated to have compromised 361 unique victim IP addresses across 47 countries.
- The exploitation activity commenced five calendar days after public disclosure of the flaw.
- Most infections were scattered across Germany (55), the U.S. (41), Turkey (38), Iran (26) and France (25).
Compiled by The WatchSomething wrong?How this is made
Why it matters
Broadcom released a fix for CVE-2026-59310 on July 29, 2026, and German incident response firm QUIRSO has since documented the flaw being chained on live vCenter appliances into a backdoor, a reverse SSH binary and Babuk-derived ransomware [1][2]. QUIRSO estimates the campaign has already compromised 361 unique victim IP addresses across 47 countries, which moves an unpatched, reachable vCenter out of the patch queue and into incident response [3].
The vulnerability itself is a directory traversal in vCenter Server carrying a CVSS score of 9.8 that can be used to execute arbitrary code [1]. QUIRSO says exploitation began five calendar days after public disclosure [4]. Infections are concentrated in Germany (55), the United States (41), Turkey (38), Iran (26) and France (25) [5]; those five countries account for roughly 51 percent of the observed victim IPs [6]. QUIRSO assesses with moderate confidence that the campaign is run by a Chinese-speaking actor likely working in the UTC+08:00 time zone [7], citing Chinese-language artifacts in attacker scripts, apparent reuse of research from a Chinese security publication, Chinese-language tooling, victimology that excludes mainland China, and working-hours patterns [8].
The mechanics matter more than the attribution, because they are what defenders can search for. On the appliance QUIRSO analyzed, the first sign was the cron daemon logging a malformed cron file named "zz-poc59310-syslog.log", followed by a curl or wget command that pulled a backdoor from 5.34.177.38:9861, ran it, and deleted the log file [9]. QUIRSO reads the filename as a direct reference to the CVE and evidence of a proof-of-concept built after the details went public [10]. The suffix mimics vCSA remote syslog naming, but the file landed in /etc/cron.d rather than the configured syslog output directory, which QUIRSO says indicates the appliance's syslog server was abused to write into a privileged execution location; at least one such file executed and dropped the "linuxFile" backdoor [11]. That implant takes commands over a WebSocket channel, runs them through /bin/sh and returns output [12]. According to QUIRSO's Denis Szadkowski, its command-and-control address is XOR-obfuscated and decoded at runtime, traffic is protected by the malware's own application-layer cryptography over an unencrypted ws:// transport, and it reconnects automatically and carries persistence routines [13].
The same appliance was also hit by CVE-2026-59309, an authentication bypass that has drawn active scanning, with activity consistent with exploitation as early as August 1, 2026 [14]. That path produced a new administrative account, "vcenter_admin", created from 146.59.252.178, with no login events recorded for the legitimate administrative account credited with creating it [15]. On August 3 the same activity performed vSphere discovery via the REST API using User-Agent strings such as "GoodMoodle-VCFleet/1.0", which QUIRSO reads as an attempt to look like VMware traffic [16]; VCF Fleet is a genuine Broadcom management capability introduced in VMware Cloud Foundation 9.0 [17]. QUIRSO found no overlap between that intrusion and the CVE-2026-59310 chain that began on the same system on August 3, and says the new account was not used in later phases [18]. If disclosure coincided with the July 29 fix, five days later is August 3 [19].
QUIRSO does not think the ransomware was the point: it describes the deployment as looking more like a smoke screen to distract from the underlying intrusion and to hinder forensics by encrypting evidence [20].
Worth watching: whether the CVE-2026-59309 scanning converts into exploitation at the scale seen for 59310 [14], and whether victim counts move past 361 IPs [3]. Worth checking now: files in /etc/cron.d on vCenter appliances, outbound ws:// sessions, privileged account creation with no preceding login for the creating account [15], and VCF-flavored user agents on REST API calls you did not initiate [16].