VSOCKpuppet is a 64-bit ELF backdoor deployed on compromised VMware ESXi hypervisors following guest-to-host virtual-machine escape. It provides persistent remote access, arbitrary shell-command execution, and bidirectional file transfer. The backdoor communicates through the VSOCK host–guest interface, allowing an operator in a guest virtual machine to control the compromised ESXi host through a channel that is not normally visible to conventional network-monitoring tools. It uses a simplified command-and-control protocol without an initial handshake. VSOCKpuppet was observed as part of an ESXi exploitation toolkit coordinated by MAESTRO and associated with exploitation assessed to involve CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226. Development artifacts associated with the toolkit contain simplified Chinese, but no specific threat actor attribution is confirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TA used an exploit tool (Hardline) to target VMware ESXi vulnerabilities (likely CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) which enable VM-to-hypervisor escape and the deployment of VSOCKpuppet malware on the ESXi host.
TA used an exploit tool (Hardline) to target VMware ESXi vulnerabilities (likely CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) which enable VM-to-hypervisor escape and the deployment of VSOCKpuppet malware on the ESXi host.
TA used an exploit tool (Hardline) to target VMware ESXi vulnerabilities (likely CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) which enable VM-to-hypervisor escape and the deployment of VSOCKpuppet malware on the ESXi host.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
VSOCKpuppet malware supports command execution and file transfer, and uses a simplified C2 protocol that does not require an initial handshake. It accepts connections via the VSOCK interface.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy backdoor used to maintain persistent control of VMware ESXi hypervisors via VSOCK-based communications, helping attackers retain access and evade traditional network monitoring.
VSOCKpuppet is a stealthy backdoor that leverages VSOCK channels to provide persistent remote control of VMware ESXi hypervisors from guest VMs, evading traditional network monitoring.
A backdoor deployed on compromised VMware ESXi hosts, using VSOCK for covert communication and persistence after a hypervisor escape exploit.
A 64-bit ELF backdoor that provides persistent remote access to compromised VMware ESXi hosts, communicating over the VSOCK protocol to evade traditional network monitoring.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.