VIRTUALPIE
MITRE ATT&CK: S1218 View on attack.mitre.org
Aliases: VIRTUALPIE
- First seen
- 2022-01-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Operating systems
- esxi
- Profile updated
- 2026-07-07 15:31:41
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
VIRTUALPIE is a lightweight backdoor written in Python that spawns an IPv6 listener on a VMware ESXi server and features command line execution, file transfer, and reverse shell capabilities. VIRTUALPIE has been in use since at least 2022 including by UNC3886 who installed it via malicious vSphere Installation Bundles (VIBs).
Detection coverage
- 22 Sigma rules
Malware & tools used
- Python (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Non-Standard Port (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- vSphere Installation Bundles (attack-pattern)
- Hypervisor CLI (attack-pattern)
Used by threat actors
- UNC3886 (threat-actor)
Reports & references
- cloud.google.com — Esxi Hypervisors Malware Persistence (report)
- MITRE ATT&CK — S1218 (report)