VIRTUALPITA
MITRE ATT&CK: S1217 View on attack.mitre.org
Aliases: VIRTUALPITA
- First seen
- 2022-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- esxi, linux
- Profile updated
- 2026-07-07 15:31:38
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
VIRTUALPITA is a passive backdoor with ESXi and Linux vCenter variants capable of command execution, file transfer, and starting and stopping processes. VIRTUALPITA has been in use since at least 2022 including by UNC3886 who leveraged malicious vSphere Installation Bundles (VIBs) for install on ESXi hypervisors.
Detection coverage
- 3 YARA rules
- 133 Sigma rules
Malware & tools used
- Python (attack-pattern)
- ESXi Administration Command (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Service Stop (attack-pattern)
- Virtual Machine Discovery (attack-pattern)
- Unix Shell (attack-pattern)
- Boot or Logon Initialization Scripts (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Prevent Command History Logging (attack-pattern)
- Non-Standard Port (attack-pattern)
Used by threat actors
- UNC3886 (threat-actor)
Detection rules
- SIGNATURE_BASE_M_APT_VIRTUALPITA_2 (yara-rule)
- SIGNATURE_BASE_M_APT_VIRTUALPITA_3 (yara-rule)
- SIGNATURE_BASE_M_APT_VIRTUALPITA_4 (yara-rule)
Reports & references
- MITRE ATT&CK — S1217 (report)
- cloud.google.com — Esxi Hypervisors Malware Persistence (report)