Tuesday, May 13, 2025
HomeCyber AttackChinese Hackers Exploit VMware ESXi Zero-Day to Execute Privileged Commands

Chinese Hackers Exploit VMware ESXi Zero-Day to Execute Privileged Commands

Published on

SIEM as a Service

Follow Us on Google News

The Chinese cyberespionage gang, identified as UNC3886, has been spotted employing a VMware ESXi zero-day vulnerability to get escalated privileges on guest virtual machines.

UNC3886 has been using malicious vSphere Installation Bundles (VIBs), typically used to maintain systems and deploy updates, to install backdoors on ESXi hypervisors, and gain access to command execution, file manipulation, and reverse shell capabilities. This activity was first reported in September 2022.

The group’s malicious activities would affect Windows virtual machines (VM), vCenter servers, and VMware ESXi hosts.

- Advertisement - Google News

UNC3886 VMware Zero-Day Attack

The gang has also used a zero-day vulnerability in VMware Tools to bypass authentication and run privileged commands on Windows, Linux, and PhotonOS (vCenter) guest VMs.

The vulnerability, CVE-2023-20867, has been given a “low severity” rating since it can only be exploited by an attacker with root access to the ESXi server.

“A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine,” VMware said in its security advisory.

Mandiant claims that UNC3886 was seen employing scripts to enumerate all ESXi hosts and their guest VMs, change lists of allowed IPs across all connected ESXi hosts, and collect credentials from compromised vCenter servers using the associated vPostgreSQL database.

Expanded UNC3886 attack path
Expanded UNC3886 attack path

“Additionally, the use of CVE-2023-20867 does not generate an authentication log event on the guest VM when commands are executed from the ESXi host,” researchers said.

The cybersecurity company also saw the group installing two backdoors (VirtualPita and VirtualGate) that used VMCI sockets for persistence and lateral movement.

In addition to enabling network segmentation bypass and the evasion of security inspections for open listening ports, the malware gives the attackers a new degree of persistence (access to the infected ESXi host is recovered by accessing a VM).

“The attack is highly targeted, with some hints of preferred governmental or government-related targets,” Fortinet said.

“The exploit requires a deep understanding of FortiOS and the underlying hardware. Custom implants show that the actor has advanced capabilities, including reverse-engineering various parts of FortiOS.”

Fortimanager attack flow
Fortimanager attack flow

According to Mandiant, UNC3886’s usage of a wide variety of new malware families and harmful tools designed specifically for the platforms they are targeting implies significant research capabilities and an out-of-the-ordinary capacity to comprehend the sophisticated technology the use of the targeted appliance.

In assaults against organizations involved in defense, technology, and telecommunications in the US and the Asia-Pacific area, UNC3886 is renowned for using zero-day vulnerabilities in firewall and virtualization solutions.

Stop Advanced Email Threats That Target Your Business Email – Try AI-Powered Email Security

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Apple Releases Security Patches to Fix Critical Data Exposure Flaws

Apple released critical security updates for macOS Sequoia 15.5 on May 12, 2025, addressing...

Lumma Stealer Upgraded with PowerShell Tools and Advanced Evasion Techniques

Sophos Managed Detection and Response (MDR) in September 2024, the notorious Lumma Stealer malware...

New Noodlophile Malware Spreads Through Fake AI Video Generation Platforms

Cybercriminals have unleashed a new malware campaign using fake AI video generation platforms as...

Kimsuky Hacker Group Deploys New Phishing Techniques and Malware Campaigns

The North Korean state-sponsored Advanced Persistent Threat (APT) group Kimsuky, also known as “Black...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Apple Releases Security Patches to Fix Critical Data Exposure Flaws

Apple released critical security updates for macOS Sequoia 15.5 on May 12, 2025, addressing...

Lumma Stealer Upgraded with PowerShell Tools and Advanced Evasion Techniques

Sophos Managed Detection and Response (MDR) in September 2024, the notorious Lumma Stealer malware...

New Noodlophile Malware Spreads Through Fake AI Video Generation Platforms

Cybercriminals have unleashed a new malware campaign using fake AI video generation platforms as...