MAESTRO is a Windows-based VMware ESXi VM-escape exploit orchestrator, also referred to as exploit.exe, observed by Huntress in intrusions investigated in December 2025. It is part of a multi-component toolkit used to escape from a guest VM to the underlying ESXi hypervisor. High-confidence reporting states that MAESTRO disables VMware VMCI devices using devcon.exe, loads an unsigned kernel driver (MyDriver.sys) via KDU/Kernel Driver Utility using a BYOVD technique to bypass Driver Signature Enforcement, coordinates the exploitation flow, monitors exploit success, restores drivers afterward, and installs a backdoor on the ESXi host.
The associated toolkit was used after initial access that Huntress assessed likely came through a compromised SonicWall VPN appliance, followed by use of a compromised Domain Admin account and lateral movement via RDP to domain controllers. The malware targeted VMware ESXi environments and supported 155 ESXi builds spanning versions 5.1 through 8.0 using build-specific offsets. Reporting links the exploit chain with moderate confidence to VMware vulnerabilities CVE-2025-22226, CVE-2025-22224, and CVE-2025-22225. Observed behavior included querying the ESXi build through VMware Guest SDK functions, leaking VMX process memory via HGFS to defeat ASLR, corrupting VMX memory via VMCI, and escaping the VMX sandbox to the ESXi kernel.
MAESTRO worked with other payloads in the toolkit, notably MyDriver.sys and the Linux ELF backdoor VSOCKpuppet. The exploitation chain wrote shellcode and VSOCKpuppet into VMX memory, after which the backdoor was deployed on the ESXi host. VSOCKpuppet provided command execution and file transfer over VSOCK, including support for GET, POST, and arbitrary shell command execution, and communicated over VSOCK port 10000 in a way described as bypassing traditional network monitoring. A Windows VSOCK client, client.exe / GetShell Plugin, was used from guest VMs to interact with the compromised hypervisor.
The activity is associated in reporting with Chinese-speaking threat actors or a Chinese-speaking development environment, based on simplified Chinese strings and PDB/build-path artifacts, including a folder translating to "All version escape - delivery." Huntress reported development artifacts dating to November 2023 and February 2024, suggesting the toolkit may have existed well before public disclosure of the related VMware flaws. Reported indicators include SHA-256 37972a232ac6d8c402ac4531430967c1fd458b74a52d6d1990688d88956791a7 for MAESTRO, and detection content includes YARA rules for the Windows MAESTRO payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VMware fixed these holes (labelled CVE-2025-22224, 22225, and 22226) on March 4, 2025, researchers found the toolkit was built as far back as November 2, 2023. This means the attackers were likely using a zero-day (a flaw unknown to the creators) for over a year.
VMware fixed these holes (labelled CVE-2025-22224, 22225, and 22226) on March 4, 2025, researchers found the toolkit was built as far back as November 2, 2023. This means the attackers were likely using a zero-day (a flaw unknown to the creators) for over a year.
VMware fixed these holes (labelled CVE-2025-22224, 22225, and 22226) on March 4, 2025, researchers found the toolkit was built as far back as November 2, 2023. This means the attackers were likely using a zero-day (a flaw unknown to the creators) for over a year.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MAESTRO is an orchestrator toolkit used to manage and automate the exploitation of VMware ESXi zero-day vulnerabilities, enabling VM escape, privilege escalation, and deployment of backdoors on the hypervisor.
MAESTRO is a sophisticated toolkit designed to exploit VMware ESXi hypervisors via VM escape vulnerabilities, allowing attackers to break out of virtual machines and gain control over the host server. It leverages zero-day vulnerabilities and advanced techniques such as VSOCK communication to evade detection and maintain persistence.
An exploit toolkit orchestrator used to escape VMware ESXi virtual machine isolation by leveraging multiple zero-day vulnerabilities, deploying shellcode, and installing a backdoor.
A toolkit/binary used post-compromise to orchestrate a VMware ESXi VM-escape chain, including disabling VMware drivers, leveraging BYOVD to load an unsigned kernel driver, and enabling hypervisor compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.