VIRTUALPITA

MITRE ATT&CK: S1217 View on attack.mitre.org

Aliases: VIRTUALPITA

First seen
2022-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
esxi, linux
Profile updated
2026-07-07 15:31:38

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

VIRTUALPITA is a passive backdoor with ESXi and Linux vCenter variants capable of command execution, file transfer, and starting and stopping processes. VIRTUALPITA has been in use since at least 2022 including by UNC3886 who leveraged malicious vSphere Installation Bundles (VIBs) for install on ESXi hypervisors.

Detection coverage

  • 3 YARA rules
  • 133 Sigma rules

Malware & tools used

  • Python (attack-pattern)
  • ESXi Administration Command (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Service Stop (attack-pattern)
  • Virtual Machine Discovery (attack-pattern)
  • Unix Shell (attack-pattern)
  • Boot or Logon Initialization Scripts (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Prevent Command History Logging (attack-pattern)
  • Non-Standard Port (attack-pattern)

Used by threat actors

Detection rules

  • SIGNATURE_BASE_M_APT_VIRTUALPITA_2 (yara-rule)
  • SIGNATURE_BASE_M_APT_VIRTUALPITA_3 (yara-rule)
  • SIGNATURE_BASE_M_APT_VIRTUALPITA_4 (yara-rule)

Reports & references

  • MITRE ATT&CK — S1217 (report)
  • cloud.google.com — Esxi Hypervisors Malware Persistence (report)

External references