Files
imposterandClaude Opus 4.8 a7451bc79a feat(attack-chains): interactive TTP graph view
D3-based TTP graph (graph/list toggle, actor filtering, zoom/pan) on attack-chain pages, with supporting diagram/flow include updates and chain content.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:49 -06:00

8.3 KiB

layout, title, subtitle, last_updated, permalink, show_ttp_overlap, ttp_data_key, stages, actors, chokepoints
layout title subtitle last_updated permalink show_ttp_overlap ttp_data_key stages actors chokepoints
attack-chain Hypervisor Compromise Attack Chain Threat actors target VMware vSphere to operate beneath the guest OS where EDR can't see - chokepoints that hold across every ESXi encryptor. 2026-04-14 /attack-chains/hypervisor-compromise/ true hypervisor_ttp_overlap
id label detection_status attacker_action systems detection_signals
initial_access Initial Access & Recon detected Exploit edge appliance / stolen creds VCSA · ESXi · vSphere API
VCSA firewall audit: SSH_BLOCKED_NEW, WEB_BLOCKED_NEW, VAMI_BLOCKED_NEW from non-PAW IP
Failed authentication from unauthorized internal IP in auth.log or vCenter UserLoginSessionEvent
Tomcat audit log showing requests to /manager/text/deploy (WAR file deployment)
id label detection_status attacker_action systems detection_signals
mgmt_takeover Mgmt Plane Takeover exploited VAMI SSH enable → shell pivot VCSA · Photon OS
VAMI log: POST /rest/com/vmware/cis/session followed by SSH enablement via PUT on port 5480
SSO audit: membership change to BashShellAdministrators group (PrincipalManagement event)
vCenter event: HostSshEnabledEvent
VCSA shell command log: interactive commands like whoami, netstat
id label detection_status attacker_action systems detection_signals
credential_theft Credential Theft exploited BRICKSTEAL: Tomcat memory + PostgreSQL creds VCSA · vCenter SSO · Active Directory
auditd key privileged: sudo usage to scrape Tomcat memory or PostgreSQL config files
HTTP requests to /web/saml2/sso/* from VCSA itself (BRICKSTEAL harvesting)
vCenter events: VmClonedEvent targeting domain controllers (offline NTDS.dit theft)
VmDiskHotPlugEvent (attacker mounting cloned DC disk)
id label detection_status attacker_action systems detection_signals
persistence Persistence detected Init script injection + transient SSO accounts VCSA · ESXi · SSO
auditd key startup_scripts: sed commands modifying /etc/sysconfig/init or /opt/vmware/etc/init.d/
auditd key perm_mod: chmod +x on init script directories
auditd key ssh_key_tamper: write to /root/.ssh/authorized_keys
AIDE integrity alert (AIDE_TRAP): differences found for /lib64 or /root/.ssh
SSO audit: transient account created and deleted within ~13 minutes
id label detection_status attacker_action systems detection_signals
lateral_movement Lateral Movement exploited vpxuser shell pivot + Ghost NIC bridging ESXi · Management VLAN · Guest VMs
vCenter event: VmNetworkAdapterAddedEvent (8.0u3+), high-fidelity Ghost NIC signal
Legacy: VmReconfiguredEvent with NIC addition to management port group
ESXi hostd.log: vpxuser shell login from VCSA IP
Windows Event 4624 (Type 3) from appliance IP using stolen service account creds
id label detection_status attacker_action systems detection_signals
exfil_impact Exfiltration & Impact detected C2 tunneling / VMDK theft / datastore encryption VCSA · Datastores · Network egress
VCSA firewall audit: INTERNET_BLOCKED, ZT_OUTBOUND_DENIED
VCSA egress to non-whitelisted destination (DoH resolvers, SOCKS proxy ports)
vCenter events: VmClonedEvent on Tier-0 VMs
Ransomware: vim-cmd vmsvc/power.off across multiple VMs followed by datastore encryption
name status initial_access mgmt_takeover credential_theft persistence lateral_movement exfil_impact
BRICKSTORM / UNC5221 Espionage Edge appliance exploit → WAR file (SLAYSTYLE) VAMI SSH enable → BashShellAdmins pivot BRICKSTEAL: Tomcat memory scrape + PostgreSQL creds sed inject into init scripts + transient SSO accounts (13-min lifecycle) vpxuser shell pivot + Ghost NIC bridging SOCKS/DoH C2 tunneling + VM clone of DCs for NTDS.dit
name status initial_access mgmt_takeover credential_theft persistence lateral_movement exfil_impact
UNC3886 Espionage Zero-day exploitation of vCenter (CVE-2023-34048) vCenter shell access + custom VIB deployment VMCI socket credential interception Malicious VIBs + modified /etc/rc.local.d scripts Custom backdoor via VMCI sockets (guest-to-host) Long-term espionage; data staging via encrypted channels
name status initial_access mgmt_takeover credential_theft persistence lateral_movement exfil_impact
UNC3944 / Scattered Spider Active Social engineering helpdesk → vSphere creds via Okta vSphere web client → SSH enable on ESXi AD credential theft via VM access + MFA bypass tokens SSH key persistence on ESXi hosts RDP/SSH from management network to guest VMs Data exfiltration + ransomware deployment via ESXi
name status initial_access mgmt_takeover credential_theft persistence lateral_movement exfil_impact
Play Ransomware Active N-day exploits (FortiOS, ESXi OpenSLP) ESXi shell access via stolen root creds Credential harvest from compromised AD rc.local.d script modification on ESXi SSH lateral between ESXi hosts ESXi datastore encryption (selective VM targeting)
name status initial_access mgmt_takeover credential_theft persistence lateral_movement exfil_impact
Alphv/BlackCat Legacy Stolen VPN/RDP creds → vCenter access vSphere web client with admin creds LSASS dump + AD enumeration (BloodHound) ESXi shell persistence + custom Linux encryptor PsExec + WMI + ESXi SSH Cross-platform Rust encryptor targeting VMFS datastores
initial_access mgmt_takeover credential_theft persistence lateral_movement exfil_impact
Management interface (VAMI 5480, SSH 22, vSphere API 443) reachable from untrusted network zone VAMI-to-shell pivot requires BashShellAdministrators membership Elevated process reads credential store or Tomcat memory Init script write + chmod to survive reboot vpxuser shell access OR Ghost NIC into management VLAN VCSA outbound to C2 OR datastore read for VMDK theft
393 days average dwell time

Most enterprise EDR has zero visibility into VCSA (Photon OS) or ESXi. Attackers who compromise the hypervisor layer operate beneath every guest VM. Credential theft, lateral movement, and persistence all occur in a blind spot where traditional endpoint detection cannot reach.

Research Methodology

Source: Kitsune pipeline over ORKL + vendor reports - 12 reports / 5 actors targeting vSphere/ESXi. Convergent techniques only.

Broader ESXi Ransomware Landscape

The two ransomware actors in this chain (Play, Alphv/BlackCat) represent a pattern shared by 10+ additional groups. SentinelOne documented that leaked Babuk source code spawned ESXi encryptors for RansomHub, LockBit, Akira, Cactus, RTM Locker, Conti successors, REvil/Revix, Rorschach/BabLock, and others. All use identical tradecraft: SSH to ESXi → vim-cmd vmsvc/power.off → encrypt /vmfs/volumes. The detection chokepoints in this chain cover all of them because the underlying prerequisites are identical regardless of which encryptor binary is deployed.

Source: SentinelOne: Multiple groups build ESXi lockers from leaked Babuk code

  • [Ransomware]({{ '/attack-chains/ransomware/' | relative_url }}) - ESXi-targeting ransomware reuses identical vSphere access patterns; 8 groups tracked in the ransomware chain
  • [Infostealers]({{ '/attack-chains/infostealers/' | relative_url }}) - Stolen VPN/RDP creds from infostealer logs provide initial vSphere access
  • [AiTM / Phishing Kits]({{ '/attack-chains/aitm/' | relative_url }}) - AiTM-compromised Okta sessions enable vSphere web client access