Malware.View on attack.mitre.org
VIRTUALPITA is a passive backdoor with ESXi and Linux vCenter variants capable of command execution, file transfer, and starting and stopping processes. VIRTUALPITA has been in use since at least 2022 including by UNC3886 who leveraged malicious vSphere Installation Bundles (VIBs) for install on ESXi hypervisors.
| Technique | Procedure example |
|---|---|
| T1036.004 Masquerade Task or Service |
VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services. |
| T1036.005 Match Legitimate Resource Name or Location |
VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary. |
| T1037 Boot or Logon Initialization Scripts |
VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems. |
| T1059.004 Unix Shell |
VIRTUALPITA has the ability to spawn a bash shell for script execution. |
| T1059.006 Python |
VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine. |
| T1105 Ingress Tool Transfer |
VIRTUALPITA has the ability to upload and download files. |
| T1489 Service Stop |
VIRTUALPITA can start and stop the `vmsyslogd` service. |
| T1570 Lateral Tool Transfer |
VIRTUALPITA is capable of file transfer and arbitrary command execution. |
| T1571 Non-Standard Port |
VIRTUALPITA has created listeners on hard coded TCP ports such as 2233, 7475, and 18098. |
| T1673 Virtual Machine Discovery |
VIRTUALPITA can target specific guest virtual machines for script execution. |
| T1675 ESXi Administration Command |
VIRTUALPITA can execute commands on guest virtual machines from compromised ESXi hypervisors. |
| T1690 Prevent Command History Logging |
VIRTUALPITA can impair logging by setting the `HISTFILE` environmental variable to `0` and stopping the `vmsyslogd` service. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.