Malware.View on attack.mitre.org
VIRTUALPIE is a lightweight backdoor written in Python that spawns an IPv6 listener on a VMware ESXi server and features command line execution, file transfer, and reverse shell capabilities. VIRTUALPIE has been in use since at least 2022 including by UNC3886 who installed it via malicious vSphere Installation Bundles (VIBs).
| Technique | Procedure example |
|---|---|
| T1059.006 Python |
VIRTUALPIE is a Python-based backdoor malware. |
| T1059.012 Hypervisor CLI |
VIRTUALPIE is capable of command line execution on compromised ESXi servers. |
| T1505.006 vSphere Installation Bundles |
VIRTUALPIE has been installed on VMware ESXi servers through malicious vSphere Installation Bundles (VIBs). |
| T1570 Lateral Tool Transfer |
VIRTUALPIE has file transfer capabilities. |
| T1571 Non-Standard Port |
VIRTUALPIE has created listeners on hard coded TCP port 546. |
| T1573.001 Symmetric Cryptography |
VIRTUALPIE can use a custom RC4 encrypted protocol for C2 communications. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.