ATT&CKSoftwareVIRTUALPIE

VIRTUALPIE

S1218

Malware.View on attack.mitre.org

About this malware

VIRTUALPIE is a lightweight backdoor written in Python that spawns an IPv6 listener on a VMware ESXi server and features command line execution, file transfer, and reverse shell capabilities. VIRTUALPIE has been in use since at least 2022 including by UNC3886 who installed it via malicious vSphere Installation Bundles (VIBs).

Techniques used6

Procedure examples6

TechniqueProcedure example
T1059.006
Python

VIRTUALPIE is a Python-based backdoor malware.

T1059.012
Hypervisor CLI

VIRTUALPIE is capable of command line execution on compromised ESXi servers.

T1505.006
vSphere Installation Bundles

VIRTUALPIE has been installed on VMware ESXi servers through malicious vSphere Installation Bundles (VIBs).

T1570
Lateral Tool Transfer

VIRTUALPIE has file transfer capabilities.

T1571
Non-Standard Port

VIRTUALPIE has created listeners on hard coded TCP port 546.

T1573.001
Symmetric Cryptography

VIRTUALPIE can use a custom RC4 encrypted protocol for C2 communications.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Google Cloud Threat Intelligence ESXi VIBs 2022 Open source
    Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.