VMware Ransomware Attack Disrupts HostDZire Services

Ransomware wipes VMware ESXi hosts at hosting provider, linked to recent VMware flaw

A ransomware attack has struck HostDZire, severely disrupting its VMware infrastructure across India, the Netherlands and the United States. The incident, widely attributed to a recently disclosed VMware vulnerability, highlights the growing risk ransomware poses to virtualisation environments.

Ransomware Attack Hits HostDZire VMware Nodes

In the early hours of 4 June 2024, HostDZire confirmed a critical security incident impacting its VMware ESXi environments. Around 02:00 UTC, multiple virtualisation nodes across three geographical regions—India, the Netherlands and the United States—were compromised. The ransomware attack resulted in the encryption of virtual disks, causing total data loss for all virtual machines (VMs) hosted on the affected nodes.

HostDZire, a cloud and hosting provider, reported that only its VMware-based services were impacted. Other services, such as KVM and Leaseweb VPS offerings, were unaffected. This points to a targeted attack on the VMware ESXi infrastructure, a platform widely used for enterprise virtualisation.

Timeline and Scope of the Incident

The attack began at approximately 02:00 UTC. Within a short window, ransomware spread across HostDZire’s VMware ESXi nodes, encrypting virtual machine disks and rendering all hosted data inaccessible. The attack affected multiple datacentres across three continents, demonstrating the scale and rapid propagation possible with modern ransomware campaigns targeting virtualisation layers.

  • Incident Start: 02:00 UTC, 4 June 2024
  • Regions Impacted: India, the Netherlands, United States
  • Systems Affected: VMware ESXi nodes (virtualisation hosts)
  • Data Impact: Total loss of data on affected VMs; full disk encryption by ransomware
  • Services Unaffected: KVM and Leaseweb VPS

HostDZire immediately began disaster recovery procedures, including infrastructure rebuilds and service redeployment. However, the company confirmed that data on the encrypted VMware hosts is irrecoverable without separate, external backups.

Attack Vector: VMware Vulnerability Exploited

HostDZire has indicated that the ransomware campaign likely exploited a recently disclosed VMware vulnerability. While the specific CVE has not been publicly identified by HostDZire, several critical VMware ESXi vulnerabilities have been disclosed in the past year, some of which allow for unauthenticated remote code execution or privilege escalation.

The attack method aligns with previously observed ESXi-targeted ransomware campaigns, where attackers exploit unpatched vulnerabilities in the hypervisor to gain access to management interfaces. Once inside, ransomware operators deploy malicious payloads that encrypt virtual disks (VMDK files) at scale, impacting all hosted VMs on the compromised node.

  • Attackers likely scanned for unpatched VMware ESXi hosts exposed to the internet.
  • By leveraging a recent vulnerability, they gained administrative access.
  • Ransomware payloads were rapidly deployed, encrypting all virtual disks on each host.
  • The attack was orchestrated to maximise disruption and data loss, typical of ESXi ransomware campaigns.

HostDZire’s immediate response included isolating affected nodes, initiating a full rebuild of the virtualisation infrastructure and advising clients to review their own backup strategies. The incident underscores the importance of timely patch management and the risks associated with internet-exposed management interfaces.

Current Status and Ongoing Impact

As of the latest update, HostDZire is in the process of rebuilding its VMware infrastructure and deploying replacement services. Clients reliant on affected VMware nodes have suffered total data loss unless they maintained independent, offline backups. HostDZire has confirmed that lost data cannot be recovered from their side.

The company has not indicated any ongoing ransomware activity, suggesting that the attack was a one-time compromise rather than a persistent threat. However, the incident remains a stark reminder of the destructive potential of ransomware when targeting virtualisation platforms.

Why It Matters

This incident demonstrates the critical risks posed by ransomware to virtualisation infrastructure. VMware ESXi has become a high-value target for attackers because of its widespread use and the potential to impact hundreds or thousands of VMs per host. A single unpatched vulnerability can expose entire environments to catastrophic data loss.

Immediate Steps for Organisations Using VMware

  • Apply the latest patches for VMware ESXi and related management tools without delay.
  • Restrict external access to management interfaces, using VPNs or dedicated networks.
  • Maintain verified, offline backups of critical systems and test restoration procedures regularly.

Organisations are urged to review their virtualisation security posture in light of this attack, focusing on patch management, secure access controls and robust backup strategies.

Originally reported by hostdzire.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call