Skip to main content

Malware Persistence within VMware ESXi Hypervisors

Three new malware tools discovered by Mandiant include VIRTUALPITA, VIRTUALPIE, and VIRTUALGATE

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Three new malware tools discovered by Mandiant include VIRTUALPITA, VIRTUALPIE, and VIRTUALGATE


Threat details

Introduction

VMware has released guidance for specialised malware that leverages unsigned vSphere Installation Bundles (VIBs) to install additional malware. Mandiant researchers discovered two backdoors, which they named VIRTUALPITA and VIRTUALPIE, as well as a dropper named VIRTUALGATE on compromised ESXi Hypervisor systems. 

An attacker with administrative privileges (root) on an ESXi host could install a malicious VIB to first install a backdoor then the dropper, at which point the attacker could drop further payloads. VMware says that there is no evidence that a vulnerability in a VMware product was exploited to gain access to ESXi during their investigations. 


Remediation advice

Affected organisation are encouraged to read VMware's Mitigation and Threat Hunting Guidance for Unsigned vSphere Installation Bundles (VIBs) - 89619, which points to additional resources and the information below.

In addition to implementing various operational security best practices mentioned in Protecting vSphere From Specialized Malware to prevent an initial compromise, VMware recommends enablement of the Secureboot feature in ESXi to mitigate the risk of malicious actors persisting on a compromised ESXi host via malicious VIB installation. Secure boot was designed to disallow installation of unsigned VIBs on an ESXi host. In addition, secure boot disallows the "--force" flag which would normally allow an administrator to bypass acceptance level settings on the ESXi host. 
 
To enable Secureboot perform the following steps: 

Please contact your hardware vendor for steps on how to enable UEFI / Secureboot for your system.

Enabling Secureboot on ESXi: UEFI Secure Boot for ESXi Hosts (vmware.com) 

  • Run the Secure boot validation script: /usr/lib/vmware/secureboot/bin/secureBoot.py -c 

      - If 7.0 u2 or later and the host has a TPM, please see the following document:  Enable or Disable the Secure Boot Enforcement for a Secure ESXi Configuration (vmware.com) 


Last edited: 30 September 2022 3:43 pm