ATT&CKReferencesGoogle Cloud Threat Intelligence ESXi VIBs 2022

Google Cloud Threat Intelligence ESXi VIBs 2022

Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025.

Open the source

Techniques2

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupUNC3886

UNC3886 has used MiniDump to dump process memory and search for cleartext credentials.

T1036.004
Masquerade Task or Service
MalwareVIRTUALPITA

VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services.

T1036.005
Match Legitimate Resource Name or Location
MalwareVIRTUALPITA

VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary.

T1037
Boot or Logon Initialization Scripts
MalwareVIRTUALPITA

VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems.

T1037.004
RC Scripts
GroupUNC3886

UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence.

T1059.001
PowerShell
GroupUNC3886

UNC3886 has used a PowerShell script to search memory dumps for credentials.

T1059.003
Windows Command Shell
GroupUNC3886

UNC3886 has executed Windows commands on guest virtual machines through `vmtoolsd.exe`.

T1059.004
Unix Shell
MalwareVIRTUALPITA

VIRTUALPITA has the ability to spawn a bash shell for script execution.

T1059.004
Unix Shell
GroupUNC3886

UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs).

T1059.006
Python
MalwareVIRTUALPITA

VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine.

T1059.006
Python
MalwareVIRTUALPIE

VIRTUALPIE is a Python-based backdoor malware.

T1059.012
Hypervisor CLI
MalwareVIRTUALPIE

VIRTUALPIE is capable of command line execution on compromised ESXi servers.

T1059.012
Hypervisor CLI
GroupUNC3886

UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal.

T1070.004
File Deletion
GroupUNC3886

UNC3886 has used the the esxcli command line to remove files created by malicious vSphere Installation Bundles from disk.

T1083
File and Directory Discovery
GroupUNC3886

UNC3886 has used `vmtoolsd.exe` to enumerate files on guest machines.

T1105
Ingress Tool Transfer
MalwareVIRTUALPITA

VIRTUALPITA has the ability to upload and download files.

T1218.011
Rundll32
GroupUNC3886

UNC3886 has used rundll32.exe to execute MiniDump for dumping LSASS process memory.

T1489
Service Stop
MalwareVIRTUALPITA

VIRTUALPITA can start and stop the `vmsyslogd` service.

T1505.006
vSphere Installation Bundles
GroupUNC3886

UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors.

T1505.006
vSphere Installation Bundles
MalwareVIRTUALPIE

VIRTUALPIE has been installed on VMware ESXi servers through malicious vSphere Installation Bundles (VIBs).

T1548
Abuse Elevation Control Mechanism
GroupUNC3886

UNC3886 has used vSphere Installation Bundles (VIBs) that contained modified descriptor XML files with the `acceptance-level` set to `partner` which allowed for privilege escalation.

T1555.005
Password Managers
GroupUNC3886

UNC3886 has targeted KeyPass password database files for credential access.

T1560.001
Archive via Utility
GroupUNC3886

UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems.

T1570
Lateral Tool Transfer
MalwareVIRTUALPIE

VIRTUALPIE has file transfer capabilities.

T1570
Lateral Tool Transfer
MalwareVIRTUALPITA

VIRTUALPITA is capable of file transfer and arbitrary command execution.

T1571
Non-Standard Port
MalwareVIRTUALPIE

VIRTUALPIE has created listeners on hard coded TCP port 546.

T1571
Non-Standard Port
MalwareVIRTUALPITA

VIRTUALPITA has created listeners on hard coded TCP ports such as 2233, 7475, and 18098.

T1573.001
Symmetric Cryptography
MalwareVIRTUALPIE

VIRTUALPIE can use a custom RC4 encrypted protocol for C2 communications.

T1673
Virtual Machine Discovery
MalwareVIRTUALPITA

VIRTUALPITA can target specific guest virtual machines for script execution.

T1675
ESXi Administration Command
MalwareVIRTUALPITA

VIRTUALPITA can execute commands on guest virtual machines from compromised ESXi hypervisors.

T1675
ESXi Administration Command
GroupUNC3886

UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host.

T1686
Disable or Modify System Firewall
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules.

T1690
Prevent Command History Logging
MalwareVIRTUALPITA

VIRTUALPITA can impair logging by setting the `HISTFILE` environmental variable to `0` and stopping the `vmsyslogd` service.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.