Detect and Response to VMware ransomware attacks, important take-aways for OT infrastructure

November 12, 2025 @ 13:55 - 14:30

  • Main Track

About Session

Technical Level: Intermediate / Advanced

Virtualization has become standard in OT networks, but it also introduces new risks. This session explores how ransomware groups increasingly target VMware-based infrastructures, exploiting poor segmentation and misconfigurations to breach OT systems. Drawing on real-world incident response cases, Truesec experts will share insights into ESXi-targeting ransomware, including the impact of Babuk source code leaks, malware TTPs, and recovery best practices. Attendees will gain actionable strategies to secure virtualized OT environments and prevent lateral movement across critical systems.

Speakers

Nicklas Keijser

Nicklas Keijser

OT lead - Detection Services, Truesec