CTIPilot

VMware vCenter Server

product · product:vmware-vcenter-server

Coverage timeline
2
first 2026-07-19 → last 2026-07-30
Peak priority
high
1 high · 1 notable
Sources cited
17
15 hosts
Sections touched
2
active-threats, trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
11
pinned v19.2 · see below

ATT&CK techniques

11 techniques observed across 2 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-30/vmware-vmsa-2026-0006-vcenter-auth-bypass-vmxnet3-escape · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

Execution TA0002

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-07-30/vmware-vmsa-2026-0006-vcenter-auth-bypass-vmxnet3-escape · ATT&CK page ↗

Persistence TA0003

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-07-30/vmware-vmsa-2026-0006-vcenter-auth-bypass-vmxnet3-escape · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

Privilege Escalation TA0004

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-07-30/vmware-vmsa-2026-0006-vcenter-auth-bypass-vmxnet3-escape · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1611Escape to Host×1

Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.

Evidence: 2026-07-30/vmware-vmsa-2026-0006-vcenter-auth-bypass-vmxnet3-escape · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

Credential Access TA0006

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

Command and Control TA0011

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-07-30/vmware-vmsa-2026-0006-vcenter-auth-bypass-vmxnet3-escape · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1486Data Encrypted for Impact×2

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-30/vmware-vmsa-2026-0006-vcenter-auth-bypass-vmxnet3-escape · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

T1490Inhibit System Recovery×1

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.

Evidence: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · ATT&CK page ↗

Story timeline

  1. 2026-07-30VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape
    trending-vulnerabilitiesBroadcom patches two pre-auth CVSS 9.8 flaws in vCenter and a VM escape in the VMXNET3 adapter; no workaround exists for any of the five
  2. 2026-07-19Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware
    active-threatsRomanian land-registry authority ANCPI down for days after a cyberattack; data-leak operator ByteToBreach claims theft and ransomware

Where this entity is cited

  • active-threats1
  • trending-vulnerabilities1

Source distribution

  • go4it.ro2 (12%)
  • thehackernews.com2 (12%)
  • advisories.ncsc.nl1 (6%)
  • cisa.gov1 (6%)
  • digi24.ro1 (6%)
  • helpnetsecurity.com1 (6%)
  • infosecurity-magazine.com1 (6%)
  • kelacyber.com1 (6%)
  • other7 (41%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (17)

Entries about VMware vCenter Server (2)

2026-07-30 · view entry permalink →

HIGHCVE-2026-59309 +4exploitedupdatedNATOA1

VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape

Broadcom published VMSA-2026-0006 on 2026-07-29, covering five vulnerabilities across VMware ESX, vCenter, Workstation and Fusion, and stating that they "were privately reported to Broadcom" with updates available to remediate them (Broadcom, 2026-07-29). Three national CERTs picked it up immediately: NCSC-CH on 2026-07-29 (NCSC Switzerland, 2026-07-29), NCSC-NL on 2026-07-29 (NCSC-NL, 2026-07-29), and BSI CERT-Bund, whose advisory is dated 2026-07-28 with a 2026-07-29 revision (BSI CERT-Bund, 2026-07-29).

Two of the five sit on vCenter and need no credentials. CVE-2026-59309 (CVSS 9.8) is an authentication bypass in the VMware Directory Service, and Broadcom's own attack-vector text is unambiguous about the prerequisite: "a malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system" (Broadcom, 2026-07-29). CVE-2026-59310, also CVSS 9.8, is a directory-traversal flaw in vCenter's Syslog server that reaches arbitrary code execution through manipulated file and directory paths (Broadcom, 2026-07-29). vCenter is the control plane for an entire virtual estate: an unauthenticated path into it is a path to every workload it manages, which is why an anonymous network-reachable bypass warrants out-of-cycle handling even with no exploitation reported.

The third flaw crosses the isolation boundary in the other direction. CVE-2026-47876 (CVSS 9.3) is an out-of-bounds write in the VMXNET3 virtual network adapter, and Broadcom scopes it precisely: "a malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue" (Broadcom, 2026-07-29). That precondition is the useful part of the triage: exposure is determined by adapter configuration rather than by ESX version alone, so the inventory question is which guests run VMXNET3 and how much you trust whoever administers them.

Two lower-severity issues complete the advisory. CVE-2026-41703 is an out-of-bounds read that Broadcom scores differently by product, 7.6 on ESX, where it says a denial of service of the host process is the more likely outcome than information disclosure, against 2.7 on Workstation and Fusion, where it restricts the impact to information disclosure (Broadcom, 2026-07-29). CVE-2026-41709 is insufficient logging on ESX that allows an administrator to act without the action being recorded (Broadcom, 2026-07-29), minor as a vulnerability, but worth noting for anyone who treats ESX audit logs as a complete record during an investigation.

Two product families beyond the obvious ones are in scope and are easy to miss on a first read of the advisory: Broadcom lists VMware Telco Cloud Platform and VMware Telco Cloud Infrastructure as impacted, with their own knowledge-base fix path rather than the vCenter and ESXi build numbers below (Broadcom, 2026-07-29). Any telco operator running those stacks needs to follow that path rather than assuming the vSphere builds cover them.

Fixed builds differ per flaw and per track. vCenter takes 9.1.0.0300, 9.0.2.0100 or 8.0 U3k, with Cloud Foundation 5.x served by an async patch to 8.0 U3k; the VMXNET3 escape is fixed in ESXi-9.1.0.0200, ESXi-9.0.2.0100 and ESXi80U3k (Broadcom, 2026-07-29). Broadcom records no workaround for any of the five, which removes the usual option of mitigating while the maintenance window is arranged.

Nothing here is reported exploited. Broadcom states the vulnerabilities "were privately reported to Broadcom" and credits Atredis Partners, Nguyen Hoang Thach of STARLabs SG working with Pwn2Own held by the Zero Day Initiative, an independent researcher, and CrowdStrike (Broadcom, 2026-07-29), and none of the three national CERTs reports in-the-wild activity. What earns this out-of-cycle attention is the reachability profile rather than an exploitation signal: two anonymous network paths into a virtualization control plane, with no interim control available.

Detection on the vCenter side means watching the two named services rather than the appliance generally: authentication events from the Directory Service, where a successful bind that no operator session accounts for is the signal, and Syslog-server request logging, where path-traversal sequences in a requested file or directory path have no legitimate counterpart. For the guest-to-host escape the telemetry is host-side, hypervisor crash and process-fault records on ESX hosts running VMXNET3 guests, since a failed escape attempt is far more likely to surface as an anomalous fault than as a clean compromise. On hardening, NCSC-NL is the source that spells out the architectural control: access to ESX and vCenter should be made available only from a separated management environment and not reachable directly from the internet or external networks (NCSC-NL, 2026-07-29). Broadcom's own advisory offers no hardening section and records "Workarounds: None" against every one of the five.

A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

Multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products.

Broadcom 2026-07-29

Compromised systems identified by QUIRSO were found to first establish contact with the attacker's domains on August 3, five days after Broadcom publicly disclosed the flaw.

followed by the deployment of a malicious cron job to establish persistence on the host using reverse_ssh

The Hacker News 2026-08-12

The presence of reverse_ssh should not, by itself, be treated as proof of malicious activity.

In combination with unauthorized installation, unexpected outbound connections or execution on a vulnerable vCenter appliance, however, it is a high-priority indicator requiring investigation.

QUIRSO GmbH 2026-08-10

Current exploitation status: Actively Exploited

NCSC Switzerland 2026-07-29

The digital forensics company assessed a suspected advanced persistent threat (APT) actor was responsible, counting 361 victim IP addresses across 47 countries

Infosecurity Magazine, citing QUIRSO GmbH 2026-08-14

The deployment [of Babuk-derived ransomware] may not have been the primary objective of the campaign

The Hacker News, paraphrasing QUIRSO's assessment
Updaterun 2026-08-13T0412Z-intelactionscvesevidenceregionssectorssourcestagstechniquesbody

The entry on Broadcom's VMSA-2026-0006 recorded five vCenter, ESX, Workstation and Fusion flaws, noted that none was reported exploited and that all had been reported privately to Broadcom. One of them has now been confirmed in use against real estates.

QUIRSO, a German security firm, reports that an incident-response engagement gave it visibility into an exploitation campaign against internet-accessible vCenter systems using CVE-2026-59310, the CVSS 9.8 directory traversal in the vCenter Syslog server that reaches arbitrary code execution from network access alone (QUIRSO, 2026-08-10). The timeline is the part that should reset patch priorities: "Compromised systems identified by QUIRSO were found to first establish contact with the attacker's domains on August 3, five days after Broadcom publicly disclosed the flaw" (The Hacker News, 2026-08-12). QUIRSO records 361 unique victim IP addresses across 47 countries, with Germany, the United States, Turkey, Iran and France the most affected and 185 of the 361 addresses in those five countries; it is explicit that an address does not correspond to an organisation, since some belong to hosting providers and shared infrastructure. By 5 August, 343 of the 361 addresses had already appeared, the campaign reached roughly 95 per cent of its observed footprint within three days of starting (QUIRSO, 2026-08-10). QUIRSO assesses that while the attacker might have had prior knowledge of the flaw, the correlation with disclosure suggests the advisory itself was the campaign's starting point.

Switzerland's NCSC updated its own VMSA-2026-0006 advisory on 12 August, setting "Current exploitation status: Actively Exploited" and citing QUIRSO's report (NCSC-CH, 2026-08-12).

What the attacker does after landing. The chain reported is path-traversal activity consistent with the flaw, "followed by the deployment of a malicious cron job to establish persistence on the host using reverse_ssh" (The Hacker News, 2026-08-12), an open-source SSH-based reverse-shell framework whose legitimate penetration-testing features include automatic connect-back, port forwarding and file transfer. The choice is a deliberate one about direction of travel: the control channel is established outbound from the appliance, which sidesteps controls built to stop unsolicited inbound access (QUIRSO, 2026-08-10). QUIRSO says a follow-up publication examining the attacker's tradecraft, infrastructure and post-exploitation activity is planned, and that further detection content is being released in coordination with law-enforcement partners.

A second, separate signal sits alongside it and should not be merged with the first. The Hacker News reports Defused Cyber observing a spike in scanning against vCenter (version probes and walks of the single-sign-on flow) that it associates with CVE-2026-59309, the unauthenticated Directory Service authentication bypass from the same advisory. QUIRSO's co-founder Denis Szadkowski told the outlet there is not enough evidence to correlate that scanning with the intrusion set behind CVE-2026-59310, adding that "the forensic evidence strongly points toward CVE-2026-59310 as the initial access vector" for the compromises QUIRSO investigated (The Hacker News, 2026-08-12). Two flaws in one advisory are drawing attention independently; only one has confirmed compromises behind it.

Detection concepts, telemetry class first. The behaviours worth hunting are all unusual for a management appliance rather than unusual in general. In egress and flow records, an SSH-protocol session initiated from a vCenter appliance to an external destination inverts the normal direction of vCenter traffic, which is inbound administrative access and outbound management of hosts. In configuration and scheduling state on the appliance, cron or scheduled entries that no platform-engineering change record accounts for are the persistence artefact reported here. In process telemetry, execution lineage descending from the Syslog service is the exploitation artefact. QUIRSO's own framing of the tool is the right calibration and applies to any dual-use binary: "The presence of reverse_ssh should not, by itself, be treated as proof of malicious activity.", "In combination with unauthorized installation, unexpected outbound connections or execution on a vulnerable vCenter appliance, however, it is a high-priority indicator requiring investigation." (QUIRSO, 2026-08-10)

Triage: administrators do legitimately place scheduled jobs on appliances and do run SSH from jump hosts, so neither artefact alone resolves. What separates this activity is the appliance being the SSH client toward an external network, a scheduled entry created outside a change window and not present in the platform team's configuration baseline, and either appearing on a vCenter whose build predates the VMSA-2026-0006 fixes. On an appliance patched before 29 July none of the three should be present at all.

Updaterun 2026-08-28T0409Z-intelcvestagstechniquessourcesevidencebody

CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog on 2026-08-18, a jurisdiction-agnostic confirmation of active exploitation, independent of any US-FCEB remediation deadline, layered on top of NCSC-CH's own actively-exploited determination already recorded above.

QUIRSO's continued work on the campaign this entry has tracked since 13 August now attributes the activity to a suspected China-nexus actor and reports that Babuk-derived ransomware was deployed against ESXi hosts in at least one investigated case: "the digital forensics company assessed a suspected advanced persistent threat (APT) actor was responsible, counting 361 victim IP addresses across 47 countries" (Infosecurity Magazine, citing QUIRSO GmbH, 2026-08-14). The ransomware deployment (.babyk extension) is assessed by QUIRSO as plausibly a smokescreen rather than the operation's goal: "the deployment [of Babuk-derived ransomware] may not have been the primary objective of the campaign" (The Hacker News, paraphrasing QUIRSO's assessment, 2026-08-17), plausibly intended to encrypt ESXi log files and hinder forensics rather than for extortion.

Both findings warrant the same caveat this entry already applies to the CVE-2026-59309 scanning correlation: every outlet surveyed (The Hacker News, Infosecurity Magazine, and further security-press pickup) cites QUIRSO's own Medium write-ups as the sole source for the China-nexus attribution (built on a UTC+08:00 activity pattern, Chinese-language code artefacts, and reuse of a Chinese security publication) at QUIRSO's own stated moderate confidence, and for the ransomware finding. Two outlets reporting one firm's conclusion is wide distribution of a single assessor's work, not independent corroboration of it; the attribution and the ransomware-deployment finding should be read as QUIRSO's own assessment, not as cross-verified intelligence, and are recorded here on that basis rather than folded into this entry's overall A/1 rating, which reflects the multi-CERT-corroborated vulnerability and initial-exploitation facts.

Nothing in this update changes the remediation guidance already given above: patch every internet-reachable vCenter to the fixed builds, and treat any instance that was internet-reachable and unpatched between 29 July and 3 August as a compromise-assessment candidate rather than a patch-and-close item, that assessment should now explicitly include a check for Babuk-derived (.babyk) file extensions on any ESXi hosts the appliance manages, alongside the reverse_ssh persistence and cron-entry artefacts already described.

vulnerability30 Jul 04:54Zmulti-sourceOpen finding ↗

2026-07-19 · view entry permalink →

NOTABLEupdatedNATOB2

Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware

Romania's National Agency for Cadastre and Real Estate Publicity (ANCPI), the government body operating the national land-registry and cadastre platforms (the e-Terra cadastral application and RENNS) that citizens, notaries, lawyers, banks and other authorities depend on for property transactions; has had all of its IT systems, including institutional email, offline since Tuesday 14 July 2026, in what it first called a "technical incident" before confirming a cyberattack; as of 17 July the systems remained down pending investigation (Help Net Security, 2026-07-16; Public Record, 2026-07-17). A threat actor using the alias ByteToBreach posted ANCPI data for sale on a dark-web forum on 15 July, claiming to hold Romanian-citizen records and various ANCPI databases, a copied GitLab server carrying the source code for e-Terra and RENNS, and to have deployed a ransomware variant (Help Net Security, 2026-07-16); in a screenshot the attacker published, he also states he began deleting the available backups (Public Record, 2026-07-17). ANCPI states the data it administers "has not been compromised as a result of this incident", a position not yet reconciled with the attacker's claims.

KELA, which profiles ByteToBreach as a persistent data-leak operator active since June 2025, documents the actor's general initial-access tradecraft as "exploiting known vulnerabilities in cloud and corporate infrastructure, reusing stolen credentials harvested from infostealers and phishing, and at times resorting to brute force," with a victim list spanning government, banking and other sectors across multiple countries, a bank in Poland among the organizations that acknowledged their breaches (KELA Cyber, 2026-07-17). Public Record's investigation reports that ANCPI's ~1.5-million-lei framework contract for cybersecurity services required constant active services (a 24/7 call-centre, at-least-annual technical audits, and ongoing monitoring and intervention over 48 months) yet the contracted vendor's owner now characterises the firm as "just a license provider… like buying Microsoft licences on eMAG" and says he had no contractual obligation to detect an attack, a self-characterisation Public Record reports the contract's own terms directly contradict; the same reporting notes a similar December 2025 cyberattack on Romania's National Water Administration (ANAR, roughly 1,000 systems affected), an agency the same security vendors had also supplied (Public Record, 2026-07-17).

They claim to have compromised data of Romanian citizens and various ANCPI databases, made a copy of the agency's GitLab servers and the source code contained within, and deployed ransomware.

ANCPI stated that the data administered through its IT systems has not been compromised as a result of this incident.

Help Net Security 2026-07-16

Exploiting known vulnerabilities in cloud and corporate infrastructure, reusing stolen credentials harvested from infostealers and phishing, and at times resorting to brute force

KELA Cyber 2026-07-17

The hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency.

Risky Business News 2026-07-20

KELA assesses the actor behind the campaign, ByteToBreach, is likely operated by Zakaria Mahdjoub, an individual based in Oran, Algeria.

KELA Cyber Intelligence Center

atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor

au compromis serverele de autentificare; au pătruns în VMware vCenter, adică sistemul care administrează întreaga infrastructură virtuală; au enumerat toate cele 1.083 de mașini virtuale; au executat mișcare laterală în rețea; au șters aproximativ 100 de mașini virtuale; au criptat servere ESXi cu ransomware

PS News (relaying the same DNSC report) 2026-07-24

infrastructura ANCPI nu beneficia de un antivirus instalat pe serverele care rulau aplicațiile principale

nu există indicii că baza de date principală Oracle Exadata ar fi fost compromisă

go4it.ro (relaying the DNSC interim technical report) 2026-07-24
Updaterun 2026-07-21T0409Z-intelevidencesourcestagstechniquesbody

The still-open ANCPI (Romanian National Agency for Cadastre and Real Estate Publicity) incident developed on two fronts. First, an impact contradiction: on 2026-07-20 ANCPI stated publicly, following completed security verification, that its technical and legal databases had not been affected (Digi24, 2026-07-20), squarely against extortion operator ByteToBreach's earlier claim, reported by Risky Business News, that the "hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency" (Risky Business News, 2026-07-20). The agency frames the multi-day e-Terra/RENNS outage (down since 14 July) as deliberate protective isolation and says it is migrating applications to the Romanian Government Cloud, coordinated by the Special Telecommunications Service, expected to complete 22 July before any phased service restoration.

Second, actor context: KELA's updated profile assesses ByteToBreach is likely a single operator based in Oran, Algeria, active since June 2025 across forums, Dread, Telegram and a storefront, with a victim set spanning government, banking, airline and university targets across several countries, and access methods documented as cloud/corporate-infrastructure exploitation, reuse of infostealer/phishing-harvested credentials, and brute force (KELA, 2026-07-17).

Updaterun 2026-07-26T1308Z-auditaffected_productsevidencesourcestechniquesbody

The picture of the attack on ANCPI, Romania's national cadastre and land-registration agency, has changed substantially. Earlier coverage recorded the agency's own position that its databases were not affected. Romania's national cybersecurity directorate DNSC has since published an interim technical report, relayed with direct quotation by Romanian technology press, that supersedes that framing on the point that matters most: the attackers extracted approximately two million records concerning users of the payment platform, containing names, e-mail addresses, identifiers and password hashes, in the report's Romanian, "atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor" (PS News, 2026-07-24). The "databases not affected" assurance survives only in a much narrower form; DNSC states there is no indication the main Oracle Exadata database was compromised (go4it.ro, 2026-07-24), which is a different claim from "no data was taken", since a separate payment-platform datastore demonstrably was.

The intrusion path DNSC describes is the one that makes a virtualized government estate fail all at once. Per the report the attackers compromised the authentication servers, penetrated VMware vCenter (the system administering the entire virtual infrastructure) enumerated all 1,083 virtual machines, executed lateral movement, deleted approximately 100 virtual machines and encrypted ESXi servers with ransomware (PS News, 2026-07-24). Identity compromise first, then the virtualization control plane, then destruction at the hypervisor layer beneath every guest operating system, the per-VM security stack never gets a vote. Source code for the eTerra, GIS, ePayment and security modules was taken from the agency's GitLab as well. DNSC's account of why it worked is unusually blunt for a national authority; the ANCPI infrastructure had no antivirus installed on the servers running its main applications (go4it.ro, 2026-07-24), alongside known unpatched vulnerabilities and a web-application firewall retaining connection logs for only seven minutes, which is also why the forensic picture is partial. DNSC's director had already assessed on 2026-07-18 that the attack exploited already-known vulnerabilities and could have been prevented (go4it.ro, 2026-07-18).

Triage: in vCenter and ESXi audit telemetry, the discriminating sequence is not any single administrative action but the ordering, an authentication from an unusual source or service account, followed by a full inventory enumeration of virtual machines, followed by power-off or delete operations across guests that share no application grouping. Routine administration enumerates inventory constantly and backup tooling touches many VMs, so volume alone is noise; the signal is enumeration by a principal that does not normally perform it, immediately followed by destructive operations spanning unrelated workloads.

incident19 Jul 04:24Zmulti-sourceOpen finding ↗