1
Groups Using This
2
Platforms
252
Prevalence Rank
0
Known Aliases
Description

VIRTUALPITA is a passive backdoor with ESXi and Linux vCenter variants capable of command execution, file transfer, and starting and stopping processes. VIRTUALPITA has been in use since at least 2022 including by UNC3886 who leveraged malicious vSphere Installation Bundles (VIBs) for install on ESXi hypervisors.

View MITRE record ↗

Platforms
ESXiLinux
Groups Deploying VIRTUALPITA (1)
↑