Virtual Machine Discovery

T1673

Technique.View on attack.mitre.org

About this technique

An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor. For example, adversaries may enumerate a list of VMs on an ESXi hypervisor using a Hypervisor CLI such as `esxcli` or `vim-cmd` (e.g. `esxcli vm process list or vim-cmd vmsvc/getallvms`). Adversaries may also directly leverage a graphical user interface, such as VMware vCenter, in order to view virtual machines on a host.

Adversaries may use the information from Virtual Machine Discovery during discovery to shape follow-on behaviors. Subsequently discovered VMs may be leveraged for follow-on activities such as Service Stop or Data Encrypted for Impact.

Detection rules2

Rules on DetectionCode tagged with T1673.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk2

RuleTypeRiskData source
ESXi Bulk VM TerminationTTPNULLVMWare ESXi Syslog
ESXi VM DiscoveryTTPNULLVMWare ESXi Syslog

Groups1

Software4

Campaigns0

None recorded.

Procedure examples5

Groups1

Used byProcedure example
GroupUNC3886

UNC3886 has used scripts to enumerate ESXi hypervisors and their guest VMs.

Software4

Used byProcedure example
MalwareCheerscrypt

Cheerscrypt has leveraged `esxcli vm process list` in order to gather a list of running virtual machines to terminate them.

MalwarePureCrypter

PureCrypter can identify virtual machines by querying the WMI object Win32_ComputerSystem for manufacturer and model and check it against the regular expression Microsoft|VMWare|Virtual.

MalwareQilin

Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.

MalwareVIRTUALPITA

VIRTUALPITA can target specific guest virtual machines for script execution.

References2

  1. Crowdstrike Hypervisor Jackpotting Pt 2 2021 Open source
    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.
  2. TrendMicro Play Open source
    Cj Arsley Mateo, Darrel Tristan Virtusio, Sarah Pearl Camiling, Andrei Alimboyao, Nathaniel Morales, Jacob Santos, Earl John Bareng. (2024, July 19). Play Ransomware Group’s New Linux Variant Targets ESXi, Shows Ties With Prolific Puma. Retrieved March 26, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.