VIRTUALPIE — Malware Profile
VIRTUALPIE is a lightweight backdoor written in Python that spawns an IPv6 listener on a VMware ESXi server and features command line execution, file transfer, and reverse shell capabilities. VIRTUALPIE has been in use since at least 2022 including by UNC3886 who installed it via malicious vSphere Installation Bundles (VIBs).
MITRE ATT&CK techniques (6)
- T1059.006 Python
- T1059.012 Hypervisor CLI
- T1505.006 vSphere Installation Bundles
- T1570 Lateral Tool Transfer
- T1571 Non-Standard Port
- T1573.001 Symmetric Cryptography