ATT&CKReferencesGoogle Cloud Threat Intelligence VMWare ESXi Zero-Day 2023

Google Cloud Threat Intelligence VMWare ESXi Zero-Day 2023

Alexander Marvi, Brad Slaybaugh, Ron Craft, and Rufus Brown. (2023, June 13). VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors. Retrieved March 26, 2025.

Open the source

Techniques4

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1021.004
SSH
GroupUNC3886

UNC3886 has established remote SSH access to targeted ESXi hosts.

T1027.005
Indicator Removal from Tools
GroupUNC3886

UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release.

T1057
Process Discovery
GroupUNC3886

UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host.

T1059.006
Python
GroupUNC3886

UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs.

T1059.012
Hypervisor CLI
GroupUNC3886

UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal.

T1068
Exploitation for Privilege Escalation
GroupUNC3886

UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs.

T1070.006
Timestomp
GroupUNC3886

UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs).

T1078.001
Default Accounts
GroupUNC3886

UNC3886 has harvested and used vCenter Server service accounts.

T1083
File and Directory Discovery
GroupUNC3886

UNC3886 has used `vmtoolsd.exe` to enumerate files on guest machines.

T1095
Non-Application Layer Protocol
GroupUNC3886

UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts.

T1124
System Time Discovery
GroupUNC3886

UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts.

T1505.006
vSphere Installation Bundles
GroupUNC3886

UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors.

T1570
Lateral Tool Transfer
GroupUNC3886

UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs.

T1587.004
Exploits
GroupUNC3886

UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter.

T1673
Virtual Machine Discovery
GroupUNC3886

UNC3886 has used scripts to enumerate ESXi hypervisors and their guest VMs.

T1675
ESXi Administration Command
GroupUNC3886

UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host.

T1681
Search Threat Vendor Data
GroupUNC3886

UNC3886 has replaced indicators mentioned in open-source threat intelligence publications at times under a week after their release.

T1686
Disable or Modify System Firewall
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules.

T1690
Prevent Command History Logging
GroupUNC3886

UNC3886 has tampered with and disabled logging services on targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.