Mandiant Incident Response. (2025, July 23). From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944. Retrieved October 13, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupScattered Spider | Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks. |
| T1021.004 SSH |
GroupScattered Spider | Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI. |
| T1041 Exfiltration Over C2 Channel |
GroupScattered Spider | Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool. |
| T1059.004 Unix Shell |
GroupScattered Spider | Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance. |
| T1069 Permission Groups Discovery |
GroupScattered Spider | Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments. |
| T1069.002 Domain Groups |
GroupScattered Spider | Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser. |
| T1078 Valid Accounts |
GroupScattered Spider | Scattered Spider has used compromised credentials for initial access. |
| T1082 System Information Discovery |
GroupScattered Spider | Scattered Spider has executed scripts to identify the underlying operating system to ensure it uses the correct installation package for malicious payloads. |
| T1083 File and Directory Discovery |
GroupScattered Spider | Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets. |
| T1087 Account Discovery |
GroupScattered Spider | Scattered Spider has identified vSphere administrator accounts. |
| T1087.002 Domain Account |
GroupScattered Spider | Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment. |
| T1098 Account Manipulation |
GroupScattered Spider | Scattered Spider has added accounts to the ESX Admins group to grant them full admin rights in vSphere. |
| T1105 Ingress Tool Transfer |
GroupScattered Spider | Scattered Spider has downloaded the Teleport remote access tool to compromised VMware vCenter Servers. |
| T1486 Data Encrypted for Impact |
GroupScattered Spider | Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers. |
| T1543.002 Systemd Service |
GroupScattered Spider | Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/ |
| T1555.005 Password Managers |
GroupScattered Spider | Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault. |
| T1589 Gather Victim Identity Information |
GroupScattered Spider | Scattered Spider has used information from previous data breaches to identify employee names to be used in social engineering. |
| T1598.004 Spearphishing Voice |
GroupScattered Spider | Scattered Spider has used help desk voice-based phishing and also called employees at target organizations and compelled them to navigate to fake login portals using adversary-in-the-middle toolkits. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.