Alexander Marvi, Brad Slaybaugh, Ron Craft, and Rufus Brown. (2023, June 13). VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors. Retrieved March 26, 2025.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.004 SSH |
GroupUNC3886 | UNC3886 has established remote SSH access to targeted ESXi hosts. |
| T1027.005 Indicator Removal from Tools |
GroupUNC3886 | UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release. |
| T1057 Process Discovery |
GroupUNC3886 | UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host. |
| T1059.006 Python |
GroupUNC3886 | UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs. |
| T1059.012 Hypervisor CLI |
GroupUNC3886 | UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal. |
| T1068 Exploitation for Privilege Escalation |
GroupUNC3886 | UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs. |
| T1070.006 Timestomp |
GroupUNC3886 | UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs). |
| T1078.001 Default Accounts |
GroupUNC3886 | UNC3886 has harvested and used vCenter Server service accounts. |
| T1083 File and Directory Discovery |
GroupUNC3886 | UNC3886 has used `vmtoolsd.exe` to enumerate files on guest machines. |
| T1095 Non-Application Layer Protocol |
GroupUNC3886 | UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts. |
| T1124 System Time Discovery |
GroupUNC3886 | UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts. |
| T1505.006 vSphere Installation Bundles |
GroupUNC3886 | UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors. |
| T1570 Lateral Tool Transfer |
GroupUNC3886 | UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs. |
| T1587.004 Exploits |
GroupUNC3886 | UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter. |
| T1673 Virtual Machine Discovery |
GroupUNC3886 | UNC3886 has used scripts to enumerate ESXi hypervisors and their guest VMs. |
| T1675 ESXi Administration Command |
GroupUNC3886 | UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host. |
| T1681 Search Threat Vendor Data |
GroupUNC3886 | UNC3886 has replaced indicators mentioned in open-source threat intelligence publications at times under a week after their release. |
| T1686 Disable or Modify System Firewall |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules. |
| T1690 Prevent Command History Logging |
GroupUNC3886 | UNC3886 has tampered with and disabled logging services on targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.