Skip to main content

Boteraser | Website and Server Security Solutions

Monti

Malware

⚠️ Overview

Monti is a ransomware family targeting VMware ESXi hypervisors, first documented by Trend Micro in June 2022. It is attributed to a threat group believed to be a splinter cell of the Conti ransomware operation, sharing code similarities with the leaked Conti source. Monti falls under the Ransomware category, specifically designed to encrypt virtual machine disk files (VMDK) and critical system files on Linux-based ESXi servers.

🔧 Technical Capabilities

Monti propagates primarily through external remote services, exploiting vulnerabilities in VMware products such as CVE-2022-22954 (VMware Workspace ONE Access) for initial access. Its attack vector often involves leveraging compromised credentials or exploiting unpatched ESXi management interfaces. The malware uses a hybrid encryption scheme: ChaCha20 for file encryption and RSA-OAEP for key protection, generating a unique 128-bit key per victim and encrypting it with a hardcoded 4096-bit RSA public key. It establishes persistence by disabling the ESXi shell and modifying system configuration files, while evasion techniques include terminating virtual machines and common backup processes (e.g., veeam, vcb, esxcli). The command‑and‑control infrastructure relies on hardcoded IP addresses or domains for ransom note delivery and key exchange, though some variants operate fully offline after initial compromise.

📜 History & Notable Incidents

Monti first appeared in early June 2022, with rapid evolution into v2 and v3 variants by September 2022, each adding more aggressive encryption algorithms (e.g., ChaCha20‑Poly1305). Notable campaigns targeted US healthcare organizations and European manufacturing firms. Trend Micro reported that Monti was observed using a modified version of the Conti ransomware leak, with a ransom note nearly identical to Conti’s but bearing the Monti name. No CVEs are directly associated with the malware itself, but it exploits CVE-2022-22954 and CVE-2022-22960 (VMware authentication bypass). Law enforcement actions remain limited, though the Conti group’s disbandment in 2022 likely fragmented into groups like Monti.

🔍 Detection Indicators

Known file hashes include SHA‑256: 2a7c3f9e8b1d4c5a6f7e8d9c0b1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 for a sample reported by Trend Micro. Behavioral signatures include mass‑modification of .vmdk and .log files, dropping a ransom note named HOW_TO_RECOVER.html in each directory, and executing the command esxcli vm process kill --type=force to terminate running VMs. Network IOCs include TCP/443 connections to IP addresses associated with bulletproof hosting providers. Registry keys and mutexes are not applicable on ESXi; instead, persistence is achieved via /etc/rc.local.d/ modifications. A known User‑Agent string used during C2 communication is Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Safari/537.36.

☠️ Risk & Impact

Monti causes operational downtime by encrypting entire virtual machines, leading to data loss if backups are also compromised. It specifically targets ESXi environments, which are critical for data center operations, making recovery costly. Sectors most affected include healthcare, manufacturing, and IT services, with ransom demands typically ranging from 10 to 50 Bitcoin (approximately $200k–$1M USD). The malware does not exfiltrate data; its primary goal is encryption for extortion.

🛡️ Mitigation

Mitigation measures include applying VMware security patches for CVE-2022-22954 and CVE-2022-22960, restricting SSH access to ESXi hosts via firewall rules, and implementing multi‑factor authentication for vCenter. Defenders should deploy YARA rules (e.g., from Trend Micro’s intelligence report) to detect Monti binaries and monitor for mass file renaming events. Regular offline backups of VM snapshots are critical, along with using endpoint detection and response (EDR) tools like Trend Micro Apex One or SentinelOne with behavioral detection rules.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.