VIRTUALPIE

MITRE ATT&CK: S1218 View on attack.mitre.org

Aliases: VIRTUALPIE

First seen
2022-01-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Operating systems
esxi
Profile updated
2026-07-07 15:31:41

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

VIRTUALPIE is a lightweight backdoor written in Python that spawns an IPv6 listener on a VMware ESXi server and features command line execution, file transfer, and reverse shell capabilities. VIRTUALPIE has been in use since at least 2022 including by UNC3886 who installed it via malicious vSphere Installation Bundles (VIBs).

Detection coverage

  • 22 Sigma rules

Malware & tools used

  • Python (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • vSphere Installation Bundles (attack-pattern)
  • Hypervisor CLI (attack-pattern)

Used by threat actors

Reports & references

  • cloud.google.com — Esxi Hypervisors Malware Persistence (report)
  • MITRE ATT&CK — S1218 (report)

External references