Vali Cyber ZeroLock 5 Adds MFA to Hypervisor Command Line to Combat Insider Threats
Vali Cyber's ZeroLock 5 introduces multi-factor authentication to the command line for ESX and Linux hypervisors, aiming to thwart insider threats and credential theft targeting critical virtualization infrastructure.

Vali Cyber has released ZeroLock 5, a significant update focused on bolstering hypervisor security by addressing two of the most critical attack vectors: insider threats and compromised credentials on ESX and Linux hosts.
The hypervisor layer, often overlooked by traditional security tools, has become an increasingly attractive target for sophisticated adversaries. Both ransomware operators and nation-state actors are shifting their focus from individual endpoints to the underlying virtualization infrastructure. Google Cloud's Cybersecurity Forecast 2026 highlighted this trend, identifying the hypervisor as a critical blind spot as security controls mature within guest operating systems.
Evidence of this shift is already emerging in the wild. Threat actors like ShinyHunters have been observed developing "shinysp1d3r," a ransomware-as-a-service platform specifically designed to encrypt VMware ESX environments. This is achieved by harvesting SSH keys and exploiting stolen credentials, demonstrating how a single compromised credential can lead to the compromise of numerous virtual machines before detection.
Because hypervisors operate at a layer beneath most security monitoring solutions, attackers who gain access to the command-line interface (CLI) can often operate with a high degree of stealth. ZeroLock 5's core innovation, CLI-MFA, is designed precisely to counter this threat. This feature extends multi-factor authentication to govern file access, program execution, and network access directly at the hypervisor CLI.
With CLI-MFA enabled, a stolen credential alone is no longer sufficient to compromise the system. Any operation governed by a defined rule can be configured to require a time-based one-time password (TOTP) before it can proceed. "We have seen firsthand what happens to a company after a hypervisor attack that started with one stolen credential. The aftermath is extraordinary, and it can bring production to a full stop," stated Anthony Gadient, CEO of Vali Cyber. "CLI-MFA cuts off that path. It lets our customers build a foundation that holds even when credentials are lost."
ZeroLock 5 is also engineered for scalability, catering to large enterprises with multiple data centers and segmented network zones. The collector component, responsible for communication with security agents, has been re-architected as a standalone service. This allows for remote deployment and independence from the central ZeroLock Management Console's location. Standardized, reusable deployment blueprints simplify the rollout of protection across numerous sites, enabling teams to manage security from a single, repeatable configuration.
"Patching is not a complete strategy at this layer. There will always be another ESX CVE, and an enterprise running hundreds of hosts across segmented zones cannot chase them fast enough," explained Austin Gadient, CTO of Vali Cyber. "What companies can do is make the attacker’s post-access behavior impossible. ZeroLock 5 lets them enforce that at scale, from a single blueprint, across every site."
In addition to its core MFA capabilities, ZeroLock 5 introduces several other enhancements. These include auditable policy lifecycle management with full revision tracking, standardized agent installation via named deployments, multi-SIEM activity forwarding with presets for major platforms like Microsoft Sentinel and Splunk, scheduled alert-only modes, vCenter host inventory import, support for VCF and ESX 6.7+, and simplified licensing. As attackers increasingly target the hypervisor, ZeroLock 5 provides enterprises with a robust defense mechanism to protect their critical virtualization infrastructure.
The operation, which took place on August 31, 2026, involved law enforcement agencies from the United States, Bulgaria, Hungary, and Romania. This coordinated effort successfully leveraged the Sality botnet's own peer-to-peer network to disrupt its command and control infrastructure, effectively preventing the distribution of new malware payloads.