| attack-chain |
Hypervisor Compromise Attack Chain |
Threat actors target VMware vSphere to operate beneath the guest OS where EDR can't see - chokepoints that hold across every ESXi encryptor. |
2026-04-14 |
/attack-chains/hypervisor-compromise/ |
true |
hypervisor_ttp_overlap |
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| initial_access |
Initial Access & Recon |
detected |
Exploit edge appliance / stolen creds |
VCSA · ESXi · vSphere API |
| VCSA firewall audit: SSH_BLOCKED_NEW, WEB_BLOCKED_NEW, VAMI_BLOCKED_NEW from non-PAW IP |
| Failed authentication from unauthorized internal IP in auth.log or vCenter UserLoginSessionEvent |
| Tomcat audit log showing requests to /manager/text/deploy (WAR file deployment) |
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| mgmt_takeover |
Mgmt Plane Takeover |
exploited |
VAMI SSH enable → shell pivot |
VCSA · Photon OS |
| VAMI log: POST /rest/com/vmware/cis/session followed by SSH enablement via PUT on port 5480 |
| SSO audit: membership change to BashShellAdministrators group (PrincipalManagement event) |
| vCenter event: HostSshEnabledEvent |
| VCSA shell command log: interactive commands like whoami, netstat |
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| credential_theft |
Credential Theft |
exploited |
BRICKSTEAL: Tomcat memory + PostgreSQL creds |
VCSA · vCenter SSO · Active Directory |
| auditd key privileged: sudo usage to scrape Tomcat memory or PostgreSQL config files |
| HTTP requests to /web/saml2/sso/* from VCSA itself (BRICKSTEAL harvesting) |
| vCenter events: VmClonedEvent targeting domain controllers (offline NTDS.dit theft) |
| VmDiskHotPlugEvent (attacker mounting cloned DC disk) |
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| persistence |
Persistence |
detected |
Init script injection + transient SSO accounts |
VCSA · ESXi · SSO |
| auditd key startup_scripts: sed commands modifying /etc/sysconfig/init or /opt/vmware/etc/init.d/ |
| auditd key perm_mod: chmod +x on init script directories |
| auditd key ssh_key_tamper: write to /root/.ssh/authorized_keys |
| AIDE integrity alert (AIDE_TRAP): differences found for /lib64 or /root/.ssh |
| SSO audit: transient account created and deleted within ~13 minutes |
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| lateral_movement |
Lateral Movement |
exploited |
vpxuser shell pivot + Ghost NIC bridging |
ESXi · Management VLAN · Guest VMs |
| vCenter event: VmNetworkAdapterAddedEvent (8.0u3+), high-fidelity Ghost NIC signal |
| Legacy: VmReconfiguredEvent with NIC addition to management port group |
| ESXi hostd.log: vpxuser shell login from VCSA IP |
| Windows Event 4624 (Type 3) from appliance IP using stolen service account creds |
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| exfil_impact |
Exfiltration & Impact |
detected |
C2 tunneling / VMDK theft / datastore encryption |
VCSA · Datastores · Network egress |
| VCSA firewall audit: INTERNET_BLOCKED, ZT_OUTBOUND_DENIED |
| VCSA egress to non-whitelisted destination (DoH resolvers, SOCKS proxy ports) |
| vCenter events: VmClonedEvent on Tier-0 VMs |
| Ransomware: vim-cmd vmsvc/power.off across multiple VMs followed by datastore encryption |
|
|
|
| name |
status |
initial_access |
mgmt_takeover |
credential_theft |
persistence |
lateral_movement |
exfil_impact |
| BRICKSTORM / UNC5221 |
Espionage |
Edge appliance exploit → WAR file (SLAYSTYLE) |
VAMI SSH enable → BashShellAdmins pivot |
BRICKSTEAL: Tomcat memory scrape + PostgreSQL creds |
sed inject into init scripts + transient SSO accounts (13-min lifecycle) |
vpxuser shell pivot + Ghost NIC bridging |
SOCKS/DoH C2 tunneling + VM clone of DCs for NTDS.dit |
|
| name |
status |
initial_access |
mgmt_takeover |
credential_theft |
persistence |
lateral_movement |
exfil_impact |
| UNC3886 |
Espionage |
Zero-day exploitation of vCenter (CVE-2023-34048) |
vCenter shell access + custom VIB deployment |
VMCI socket credential interception |
Malicious VIBs + modified /etc/rc.local.d scripts |
Custom backdoor via VMCI sockets (guest-to-host) |
Long-term espionage; data staging via encrypted channels |
|
| name |
status |
initial_access |
mgmt_takeover |
credential_theft |
persistence |
lateral_movement |
exfil_impact |
| UNC3944 / Scattered Spider |
Active |
Social engineering helpdesk → vSphere creds via Okta |
vSphere web client → SSH enable on ESXi |
AD credential theft via VM access + MFA bypass tokens |
SSH key persistence on ESXi hosts |
RDP/SSH from management network to guest VMs |
Data exfiltration + ransomware deployment via ESXi |
|
| name |
status |
initial_access |
mgmt_takeover |
credential_theft |
persistence |
lateral_movement |
exfil_impact |
| Play Ransomware |
Active |
N-day exploits (FortiOS, ESXi OpenSLP) |
ESXi shell access via stolen root creds |
Credential harvest from compromised AD |
rc.local.d script modification on ESXi |
SSH lateral between ESXi hosts |
ESXi datastore encryption (selective VM targeting) |
|
| name |
status |
initial_access |
mgmt_takeover |
credential_theft |
persistence |
lateral_movement |
exfil_impact |
| Alphv/BlackCat |
Legacy |
Stolen VPN/RDP creds → vCenter access |
vSphere web client with admin creds |
LSASS dump + AD enumeration (BloodHound) |
ESXi shell persistence + custom Linux encryptor |
PsExec + WMI + ESXi SSH |
Cross-platform Rust encryptor targeting VMFS datastores |
|
|
| initial_access |
mgmt_takeover |
credential_theft |
persistence |
lateral_movement |
exfil_impact |
| Management interface (VAMI 5480, SSH 22, vSphere API 443) reachable from untrusted network zone |
VAMI-to-shell pivot requires BashShellAdministrators membership |
Elevated process reads credential store or Tomcat memory |
Init script write + chmod to survive reboot |
vpxuser shell access OR Ghost NIC into management VLAN |
VCSA outbound to C2 OR datastore read for VMDK theft |
|