VirtualPie is a backdoor associated with espionage operations targeting VMware virtualization infrastructure, particularly ESXi hosts in vSphere environments. It has been publicly linked to activity attributed to the China-nexus threat actor UNC3886 and has been observed alongside the related backdoor VirtualPita in intrusions against compromised VMware environments.
The malware is designed for use on ESXi systems, a platform that is attractive to advanced operators because hypervisors provide high-value access while often lacking the endpoint visibility common on conventional servers and workstations. VirtualPie has been reported in campaigns involving exploitation of VMware vCenter Server vulnerabilities, including CVE-2023-34048, and deployment via malicious vSphere Installation Bundles. Its use fits a broader pattern of platform-specific tooling developed to maintain stealthy, persistent access in low-visibility infrastructure layers.
Available reporting supports that VirtualPie functions as a listener-based backdoor on ESXi, accepting inbound connections on a hard-coded TCP port. Its role in these operations is consistent with post-compromise persistence and remote access on virtualized infrastructure used for long-term espionage. Organizations operating VMware vSphere and ESXi, especially those with limited logging and forensic coverage on hypervisors, are the primary at-risk environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In January 2024, Chinese state hackers were linked to attacks exploiting a critical vCenter Server zero-day (CVE-2023-34048) since late 2021, which led to the deployment of VirtualPita and VirtualPie backdoors on compromised ESXi systems.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... VIRTUALPIE ... (v1.0) ...
VIRTUALPIE (v1.0)
Backdoor deployed on compromised ESXi systems following exploitation of VMware vCenter Server zero-day CVE-2023-34048.
Backdoor malware deployed on ESXi hosts, used by threat actors to maintain persistent access and control over compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.