Malware Persistence within VMware ESXi Hypervisors
Three new malware tools discovered by Mandiant include VIRTUALPITA, VIRTUALPIE, and VIRTUALGATE
Summary
Three new malware tools discovered by Mandiant include VIRTUALPITA, VIRTUALPIE, and VIRTUALGATE
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware has released guidance for specialised malware that leverages unsigned vSphere Installation Bundles (VIBs) to install additional malware. Mandiant researchers discovered two backdoors, which they named VIRTUALPITA and VIRTUALPIE, as well as a dropper named VIRTUALGATE on compromised ESXi Hypervisor systems.
An attacker with administrative privileges (root) on an ESXi host could install a malicious VIB to first install a backdoor then the dropper, at which point the attacker could drop further payloads. VMware says that there is no evidence that a vulnerability in a VMware product was exploited to gain access to ESXi during their investigations.
Remediation advice
Affected organisation are encouraged to read VMware's Mitigation and Threat Hunting Guidance for Unsigned vSphere Installation Bundles (VIBs) - 89619, which points to additional resources and the information below.
In addition to implementing various operational security best practices mentioned in Protecting vSphere From Specialized Malware to prevent an initial compromise, VMware recommends enablement of the Secureboot feature in ESXi to mitigate the risk of malicious actors persisting on a compromised ESXi host via malicious VIB installation. Secure boot was designed to disallow installation of unsigned VIBs on an ESXi host. In addition, secure boot disallows the "--force" flag which would normally allow an administrator to bypass acceptance level settings on the ESXi host.
To enable Secureboot perform the following steps:
Please contact your hardware vendor for steps on how to enable UEFI / Secureboot for your system.
Enabling Secureboot on ESXi: UEFI Secure Boot for ESXi Hosts (vmware.com)
-
Run the Secure boot validation script: /usr/lib/vmware/secureboot/bin/secureBoot.py -c
- If 7.0 u2 or later and the host has a TPM, please see the following document: Enable or Disable the Secure Boot Enforcement for a Secure ESXi Configuration (vmware.com)
Definitive source of threat updates
Last edited: 30 September 2022 3:43 pm