CrowdStrike Uncovers Hackers Hiding Malicious Commands on VMware ESX Servers
Security researchers at CrowdStrike have detected a concerning trend: attackers are using command obfuscation techniques to hide malicious activity on VMware ESX servers. ESX is a widely used virtualisation platform that many businesses rely on to run multiple virtual machines on a single physical server, making it a high-value target for cybercriminals looking to gain broad access to an organisation's systems.
By disguising shell commands, attackers can slip past basic security monitoring tools that look for known malicious patterns. This kind of obfuscation makes it harder for IT teams to spot suspicious behaviour before real damage—such as data theft, ransomware deployment, or further network compromise—occurs. CrowdStrike's findings highlight the growing sophistication of threat actors targeting virtualisation infrastructure, which is often less closely monitored than standard servers or endpoints.
For small and medium businesses that use virtualised environments, even through a managed IT provider, this development is a reminder that foundational infrastructure like ESX servers needs the same level of security scrutiny as everyday devices. Attackers increasingly view virtualisation platforms as a stepping stone to broader network access, making early detection critical.