VIRTUALPITA

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[VIRTUALPITA](https://attack.mitre.org/software/S1217) is a passive backdoor with ESXi and Linux vCenter variants capable of command execution, file transfer, and starting and stopping processes. [VIRTUALPITA](https://attack.mitre.org/software/S1217) has been in use since at least 2022 including by [UNC3886](https://attack.mitre.org/groups/G1048) who leveraged malicious vSphere Installation Bundles (VIBs) for install on ESXi hypervisors.(Citation: Google Cloud Threat Intelligence ESXi VIBs 2022)

Associated Techniques (12)
ID ATT&CK Tactics
T1036.004 Masquerade Task or Service -
T1036.005 Match Legitimate Resource Name or Location -
T1037 Boot or Logon Initialization Scripts -
T1059.004 Unix Shell -
T1059.006 Python -
T1105 Ingress Tool Transfer -
T1489 Service Stop -
T1562.003 Impair Command History Logging -
T1570 Lateral Tool Transfer -
T1571 Non-Standard Port -
T1673 Virtual Machine Discovery -
T1675 ESXi Administration Command -
Used by Actors (1)
Metadata
ID: 606
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00