Researchers from cyber threat intelligence company Mandiant on Thursday 29th published information on two malware leveraging unsigned vSphere Installation Bundles (“VIBs”) to install backdoors VirtualPita and VirtualPie on compromised ESXi host. First I would like to point out that malicious actors MUST have administrative privileges on the ESXi host to perform an attack. Also, there…
Read moreTag: malware
VirtualPita, VirtualPie – new malware backdoors VMware ESXi servers to hijack virtual machines
The malicious actors found the new method of taking over the control of VMware ESXi hypervisors to control vCenter servers and virtual machines for Windows and Linux while avoiding detection. Attackers are using malicious vSphere Installation Bundles (“VIBs”) to install multiple backdoors across ESXi hypervisors. The malware is hidden in VIB payloads. Researchers from Mandiant…
Read more