ATT&CKSoftwareVIRTUALPITA

VIRTUALPITA

S1217

Malware.View on attack.mitre.org

About this malware

VIRTUALPITA is a passive backdoor with ESXi and Linux vCenter variants capable of command execution, file transfer, and starting and stopping processes. VIRTUALPITA has been in use since at least 2022 including by UNC3886 who leveraged malicious vSphere Installation Bundles (VIBs) for install on ESXi hypervisors.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1036.004
Masquerade Task or Service

VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services.

T1036.005
Match Legitimate Resource Name or Location

VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary.

T1037
Boot or Logon Initialization Scripts

VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems.

T1059.004
Unix Shell

VIRTUALPITA has the ability to spawn a bash shell for script execution.

T1059.006
Python

VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine.

T1105
Ingress Tool Transfer

VIRTUALPITA has the ability to upload and download files.

T1489
Service Stop

VIRTUALPITA can start and stop the `vmsyslogd` service.

T1570
Lateral Tool Transfer

VIRTUALPITA is capable of file transfer and arbitrary command execution.

T1571
Non-Standard Port

VIRTUALPITA has created listeners on hard coded TCP ports such as 2233, 7475, and 18098.

T1673
Virtual Machine Discovery

VIRTUALPITA can target specific guest virtual machines for script execution.

T1675
ESXi Administration Command

VIRTUALPITA can execute commands on guest virtual machines from compromised ESXi hypervisors.

T1690
Prevent Command History Logging

VIRTUALPITA can impair logging by setting the `HISTFILE` environmental variable to `0` and stopping the `vmsyslogd` service.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Google Cloud Threat Intelligence ESXi VIBs 2022 Open source
    Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.