Hypervisor CLI

T1059.012

Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org

About this technique

Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands. Hypervisor CLIs typically enable a wide variety of functionality for managing both the hypervisor itself and the guest virtual machines it hosts.

For example, on ESXi systems, tools such as `esxcli` and `vim-cmd` allow administrators to configure firewall rules and log forwarding on the hypervisor, list virtual machines, start and stop virtual machines, and more. Adversaries may be able to leverage these tools in order to support further actions, such as File and Directory Discovery or Data Encrypted for Impact.

Detection rules9

Rules on DetectionCode tagged with T1059.012.

Sigma9

RuleLevelLog source
ESXi Admin Permission Assigned To Account Via ESXCLIhighlinux / process_creation
ESXi Account Creation Via ESXCLImediumlinux / process_creation
ESXi Network Configuration Discovery Via ESXCLImediumlinux / process_creation
ESXi Storage Information Discovery Via ESXCLImediumlinux / process_creation
ESXi Syslog Configuration Change Via ESXCLImediumlinux / process_creation
ESXi System Information Discovery Via ESXCLImediumlinux / process_creation
ESXi VM Kill Via ESXCLImediumlinux / process_creation
ESXi VM List Discovery Via ESXCLImediumlinux / process_creation
ESXi VSAN Information Discovery Via ESXCLImediumlinux / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples4

Groups1

Used byProcedure example
GroupUNC3886

UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal.

Software3

Used byProcedure example
MalwareCheerscrypt

Cheerscrypt has leveraged `esxcli` in order to terminate running virtual machines.

MalwareRoyal

Royal ransomware uses `esxcli` to gather a list of running VMs and terminate them.

MalwareVIRTUALPIE

VIRTUALPIE is capable of command line execution on compromised ESXi servers.

References3

  1. Broadcom ESXCLI Reference Open source
    Broadcom. (n.d.). ESXCLI Reference. Retrieved March 27, 2025.
  2. Crowdstrike Hypervisor Jackpotting Pt 2 2021 Open source
    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.
  3. LOLESXi Open source
    Janantha Marasinghe. (n.d.). Living Off The Land ESXi. Retrieved April 14, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.