Friday, December 6, 2024
HomeCyber AttackChinese Hackers Exploit VMware ESXi Zero-Day to Execute Privileged Commands

Chinese Hackers Exploit VMware ESXi Zero-Day to Execute Privileged Commands

Published on

SIEM as a Service

The Chinese cyberespionage gang, identified as UNC3886, has been spotted employing a VMware ESXi zero-day vulnerability to get escalated privileges on guest virtual machines.

UNC3886 has been using malicious vSphere Installation Bundles (VIBs), typically used to maintain systems and deploy updates, to install backdoors on ESXi hypervisors, and gain access to command execution, file manipulation, and reverse shell capabilities. This activity was first reported in September 2022.

The group’s malicious activities would affect Windows virtual machines (VM), vCenter servers, and VMware ESXi hosts.

- Advertisement - SIEM as a Service

UNC3886 VMware Zero-Day Attack

The gang has also used a zero-day vulnerability in VMware Tools to bypass authentication and run privileged commands on Windows, Linux, and PhotonOS (vCenter) guest VMs.

The vulnerability, CVE-2023-20867, has been given a “low severity” rating since it can only be exploited by an attacker with root access to the ESXi server.

“A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine,” VMware said in its security advisory.

Mandiant claims that UNC3886 was seen employing scripts to enumerate all ESXi hosts and their guest VMs, change lists of allowed IPs across all connected ESXi hosts, and collect credentials from compromised vCenter servers using the associated vPostgreSQL database.

Expanded UNC3886 attack path
Expanded UNC3886 attack path

“Additionally, the use of CVE-2023-20867 does not generate an authentication log event on the guest VM when commands are executed from the ESXi host,” researchers said.

The cybersecurity company also saw the group installing two backdoors (VirtualPita and VirtualGate) that used VMCI sockets for persistence and lateral movement.

In addition to enabling network segmentation bypass and the evasion of security inspections for open listening ports, the malware gives the attackers a new degree of persistence (access to the infected ESXi host is recovered by accessing a VM).

“The attack is highly targeted, with some hints of preferred governmental or government-related targets,” Fortinet said.

“The exploit requires a deep understanding of FortiOS and the underlying hardware. Custom implants show that the actor has advanced capabilities, including reverse-engineering various parts of FortiOS.”

Fortimanager attack flow
Fortimanager attack flow

According to Mandiant, UNC3886’s usage of a wide variety of new malware families and harmful tools designed specifically for the platforms they are targeting implies significant research capabilities and an out-of-the-ordinary capacity to comprehend the sophisticated technology the use of the targeted appliance.

In assaults against organizations involved in defense, technology, and telecommunications in the US and the Asia-Pacific area, UNC3886 is renowned for using zero-day vulnerabilities in firewall and virtualization solutions.

Stop Advanced Email Threats That Target Your Business Email – Try AI-Powered Email Security

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Top Five Industries Most Frequently Targeted by Phishing Attacks

Researchers analyzed phishing attacks from Q3 2023 to Q3 2024 and identified the top...

Russian BlueAlpha APT Exploits Cloudflare Tunnels to Distribute Custom Malware

BlueAlpha, a Russian state-sponsored group, is actively targeting Ukrainian individuals and organizations by using...

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...

Sophisticated Celestial Stealer Targets Browsers to Steal Login Credentials

Researchers discovered Celestial Stealer, a JavaScript-based MaaS infostealer targeting Windows systems that, evading detection...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Top Five Industries Most Frequently Targeted by Phishing Attacks

Researchers analyzed phishing attacks from Q3 2023 to Q3 2024 and identified the top...

Russian BlueAlpha APT Exploits Cloudflare Tunnels to Distribute Custom Malware

BlueAlpha, a Russian state-sponsored group, is actively targeting Ukrainian individuals and organizations by using...

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...