GetShell Plugin is a Windows-based VSOCK client tool, also referred to as client.exe, used to interact with the VSOCKpuppet backdoor on compromised VMware ESXi hosts. Huntress observed it as part of a sophisticated ESXi VM-escape toolkit deployed in a December 2025 intrusion that likely began via a compromised SonicWall VPN and involved use of a compromised Domain Admin account. The broader toolkit was assessed to exploit VMware vulnerabilities CVE-2025-22226, CVE-2025-22224, and CVE-2025-22225 to escape from a guest VM into the ESXi host, after which VSOCKpuppet was installed on the hypervisor.
GetShell Plugin provides interactive shell access to the ESXi backdoor from any guest Windows VM on the compromised host by communicating over VMware VSOCK/VMCI, a channel Huntress noted is largely invisible to traditional network monitoring. Reported capabilities include arbitrary shell command execution on the hypervisor as well as file transfer operations corresponding to GET (read file) and POST (write file) functionality exposed by VSOCKpuppet. If needed, the client installs or registers VMware VSOCK components as a Winsock provider to enable communications.
The malware is associated with the same intrusion set Huntress described as likely Chinese-speaking, based on simplified Chinese development artifacts and related build evidence in the toolkit. The attack targeted VMware ESXi environments and demonstrated stealth-focused hypervisor compromise rather than conventional network-based backdoor communications. Known related indicators directly mentioned in the content include SHA-256 for client.exe / GetShell Plugin: 4614346fc1ff74f057d189db45aa7dc25d6e7f3d9b68c287a409a53c86dca25e, and Binary.zip: dc5b8f7c6a8a6764de3309279e3b6412c23e6af1d7a8631c65b80027444d62bb.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-22225 (8.2 severity score): An arbitrary write vulnerability in ESXi that allows escaping the VMX sandbox to the kernel
Of the three bugs, only one received a critical severity score: CVE-2025-22226 (7.1 severity score): An out-of-bounds read in HGFS that allows leaking memory from the VMX process
CVE-2025-22224 (9.3 severity score): A TOCTOU vulnerability in Virtual Machine Communication Interface (VMCI) leading to an out-of-bounds write, allowing code execution as the VMX process
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A post-exploitation tool that allows attackers to interact with the VSOCKpuppet backdoor on ESXi hosts from a guest Windows VM, supporting file transfer and command execution.
Windows VSOCK client used from a guest VM to connect to the ESXi-hosted VSOCKpuppet backdoor (typically CID 2 for hypervisor, port 10000). Implements handshake and length-prefixed messaging; supports get/post and interactive command execution against the hypervisor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.