UNC3944, a financially driven threat organization associated with “0ktapus,” “Octo Tempest,” and “Scattered Spider,” launched a sophisticated cyber campaign that used social engineering and hypervisor-level attacks to target VMware vSphere environments in the retail, airline, and insurance industries. Google Threat Intelligence Group (GITG) identified the campaign in mid-2025, following FBI alerts about escalation targeting U.S. […]
The post UNC3944 Attacking VMware vSphere and Enabling SSH on ESXi Hosts to Reset ‘root’ Passwords appeared first on Cyber Security News.
Read the original article: