ESXi Exploitation in the Wild
Huntress stopped an intrusion that used a VMware ESXi VM-escape toolkit after SonicWall VPN access.
Huntress reported a December 2025 intrusion in which attackers likely entered through a compromised SonicWall VPN, then moved laterally with a Domain Admin account over RDP to domain controllers. They deployed an ESXi VM-escape toolkit called MAESTRO that Huntress assesses with moderate confidence uses CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226. The toolkit supports 155 ESXi builds from versions 5.1 through 8.0 and uses KDU to load an unsigned driver. Huntress contained the activity before ransomware; simplified Chinese development strings suggest a developer in a Chinese-speaking region.