VIRTUALPITA is a backdoor used in cyber-espionage operations targeting VMware virtualization infrastructure, particularly ESXi hosts in vSphere environments. It has been associated with the China-nexus threat cluster UNC3886 and has also been linked to activity tracked as Fire Ant. The malware has been deployed after exploitation of VMware vCenter Server vulnerabilities, including CVE-2023-34048, and in some intrusions was installed on compromised ESXi systems through malicious vSphere Installation Bundles to achieve persistence across reboots.
The backdoor is designed for stealthy control of hypervisor environments and for enabling access into guest virtual machines from the ESXi host. Reported tradecraft includes use of VMCI-based channels to communicate from the host to guest VMs, allowing operators to pass arbitrary commands into guest systems while reducing visibility in conventional network monitoring. Commands relayed through this mechanism may execute inside guest Windows systems via VMware Tools processes, while activity on the ESXi host itself is less readily logged. VIRTUALPITA has also been observed suppressing forensic evidence by disabling shell history and masquerading as legitimate VMware-related services through use of VMware service names and ports.
Operationally, VIRTUALPITA supports persistent access to high-value virtualization infrastructure and facilitates post-compromise control of hosted workloads. In observed campaigns, deployment of VIRTUALPITA formed part of broader intrusion chains involving credential theft from virtualization management components, movement from vCenter to ESXi, and long-term espionage-oriented access to segmented environments. Targeting has centered on organizations operating VMware infrastructure, with hypervisors and associated management layers treated as strategic footholds because compromise can provide durable access to multiple guest systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In January 2024, Chinese state hackers were linked to attacks exploiting a critical vCenter Server zero-day (CVE-2023-34048) since late 2021, which led to the deployment of VirtualPita and VirtualPie backdoors on compromised ESXi systems.
"They deployed multiple persistent backdoors on both ESXi hosts and the vCenter to maintain access across reboots. The backdoor filename, hash, and deployment technique aligned the VIRTUALPITA malware family."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC3886 utilized backdoors such as VIRTUALPITA, and took advantage of VMCI-based channels to communicate from the ESXi host to the guest virtual machines (VM).
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Mandiant has observed a trend in which China-nexus attackers have gained access to edge devices via exploitation of vulnerabilities, particularly zero-days... If an attacker possesses an exploit for a zero-day vulnerability on these devices, they are often able to gain access to a target environment and remain undetected for an extended period of time.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
VIRTUALPITA also sets the HISTFILE to 0, which would remove any terminal history on the host system, leaving behind little forensics evidence.
Once the threat actor has disabled execInstalledOnly, they can perform a — force installation of custom malicious VIBs (vSphere Installation Bundles).
the usage of the following command to list & then terminate all VM processes using the ESXCLI, respectively. esxcli vm process list
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... VIRTUALPITA ... (v1.0) ...
VIRTUALPITA (v1.0)
Backdoor deployed on compromised ESXi systems following exploitation of VMware vCenter Server zero-day CVE-2023-34048.
A malware family of persistent backdoors deployed on VMware ESXi hosts and VMware vCenter to maintain access across reboots in a cyber-espionage campaign targeting virtualization infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.