ATT&CKReferencesMandiant VMware vSphere JUL 2025

Mandiant VMware vSphere JUL 2025

Mandiant Incident Response. (2025, July 23). From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944. Retrieved October 13, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupScattered Spider

Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks.

T1021.004
SSH
GroupScattered Spider

Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI.

T1041
Exfiltration Over C2 Channel
GroupScattered Spider

Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool.

T1059.004
Unix Shell
GroupScattered Spider

Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance.

T1069
Permission Groups Discovery
GroupScattered Spider

Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments.

T1069.002
Domain Groups
GroupScattered Spider

Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser.

T1078
Valid Accounts
GroupScattered Spider

Scattered Spider has used compromised credentials for initial access.

T1082
System Information Discovery
GroupScattered Spider

Scattered Spider has executed scripts to identify the underlying operating system to ensure it uses the correct installation package for malicious payloads.

T1083
File and Directory Discovery
GroupScattered Spider

Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets.

T1087
Account Discovery
GroupScattered Spider

Scattered Spider has identified vSphere administrator accounts.

T1087.002
Domain Account
GroupScattered Spider

Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment.

T1098
Account Manipulation
GroupScattered Spider

Scattered Spider has added accounts to the ESX Admins group to grant them full admin rights in vSphere.

T1105
Ingress Tool Transfer
GroupScattered Spider

Scattered Spider has downloaded the Teleport remote access tool to compromised VMware vCenter Servers.

T1486
Data Encrypted for Impact
GroupScattered Spider

Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers.

T1543.002
Systemd Service
GroupScattered Spider

Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/
system/teleport.service` to establish persistence for the Teleport remote access tool.

T1555.005
Password Managers
GroupScattered Spider

Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault.

T1589
Gather Victim Identity Information
GroupScattered Spider

Scattered Spider has used information from previous data breaches to identify employee names to be used in social engineering.

T1598.004
Spearphishing Voice
GroupScattered Spider

Scattered Spider has used help desk voice-based phishing and also called employees at target organizations and compelled them to navigate to fake login portals using adversary-in-the-middle toolkits.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.