Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupUNC3886 | UNC3886 has used MiniDump to dump process memory and search for cleartext credentials. |
| T1036.004 Masquerade Task or Service |
MalwareVIRTUALPITA | VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareVIRTUALPITA | VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary. |
| T1037 Boot or Logon Initialization Scripts |
MalwareVIRTUALPITA | VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems. |
| T1037.004 RC Scripts |
GroupUNC3886 | UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence. |
| T1059.001 PowerShell |
GroupUNC3886 | UNC3886 has used a PowerShell script to search memory dumps for credentials. |
| T1059.003 Windows Command Shell |
GroupUNC3886 | UNC3886 has executed Windows commands on guest virtual machines through `vmtoolsd.exe`. |
| T1059.004 Unix Shell |
MalwareVIRTUALPITA | VIRTUALPITA has the ability to spawn a bash shell for script execution. |
| T1059.004 Unix Shell |
GroupUNC3886 | UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs). |
| T1059.006 Python |
MalwareVIRTUALPITA | VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine. |
| T1059.006 Python |
MalwareVIRTUALPIE | VIRTUALPIE is a Python-based backdoor malware. |
| T1059.012 Hypervisor CLI |
MalwareVIRTUALPIE | VIRTUALPIE is capable of command line execution on compromised ESXi servers. |
| T1059.012 Hypervisor CLI |
GroupUNC3886 | UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal. |
| T1070.004 File Deletion |
GroupUNC3886 | UNC3886 has used the the esxcli command line to remove files created by malicious vSphere Installation Bundles from disk. |
| T1083 File and Directory Discovery |
GroupUNC3886 | UNC3886 has used `vmtoolsd.exe` to enumerate files on guest machines. |
| T1105 Ingress Tool Transfer |
MalwareVIRTUALPITA | VIRTUALPITA has the ability to upload and download files. |
| T1218.011 Rundll32 |
GroupUNC3886 | UNC3886 has used rundll32.exe to execute MiniDump for dumping LSASS process memory. |
| T1489 Service Stop |
MalwareVIRTUALPITA | VIRTUALPITA can start and stop the `vmsyslogd` service. |
| T1505.006 vSphere Installation Bundles |
GroupUNC3886 | UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors. |
| T1505.006 vSphere Installation Bundles |
MalwareVIRTUALPIE | VIRTUALPIE has been installed on VMware ESXi servers through malicious vSphere Installation Bundles (VIBs). |
| T1548 Abuse Elevation Control Mechanism |
GroupUNC3886 | UNC3886 has used vSphere Installation Bundles (VIBs) that contained modified descriptor XML files with the `acceptance-level` set to `partner` which allowed for privilege escalation. |
| T1555.005 Password Managers |
GroupUNC3886 | UNC3886 has targeted KeyPass password database files for credential access. |
| T1560.001 Archive via Utility |
GroupUNC3886 | UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems. |
| T1570 Lateral Tool Transfer |
MalwareVIRTUALPIE | VIRTUALPIE has file transfer capabilities. |
| T1570 Lateral Tool Transfer |
MalwareVIRTUALPITA | VIRTUALPITA is capable of file transfer and arbitrary command execution. |
| T1571 Non-Standard Port |
MalwareVIRTUALPIE | VIRTUALPIE has created listeners on hard coded TCP port 546. |
| T1571 Non-Standard Port |
MalwareVIRTUALPITA | VIRTUALPITA has created listeners on hard coded TCP ports such as 2233, 7475, and 18098. |
| T1573.001 Symmetric Cryptography |
MalwareVIRTUALPIE | VIRTUALPIE can use a custom RC4 encrypted protocol for C2 communications. |
| T1673 Virtual Machine Discovery |
MalwareVIRTUALPITA | VIRTUALPITA can target specific guest virtual machines for script execution. |
| T1675 ESXi Administration Command |
MalwareVIRTUALPITA | VIRTUALPITA can execute commands on guest virtual machines from compromised ESXi hypervisors. |
| T1675 ESXi Administration Command |
GroupUNC3886 | UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host. |
| T1686 Disable or Modify System Firewall |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules. |
| T1690 Prevent Command History Logging |
MalwareVIRTUALPITA | VIRTUALPITA can impair logging by setting the `HISTFILE` environmental variable to `0` and stopping the `vmsyslogd` service. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.