Threat actors continually adapt tactics to continue to gain more effective attacks that glean the most data. That is no secret.

By increasing the development and use of specialized techniques, threat actors optimize the ability to steal intellectual property, ransom and extort their victims, and extort victims’ customers.

A new variant of malware targeting VMware’s vSphere ended up discovered by Mandiant researchers where threat actors may have used operational security weaknesses to compromise a mutual customer.

To that end, Mandiant found no evidence a vulnerability in a VMware product was exploited to gain access to ESXi during their investigations, the company said in a post. Mandiant named the malware artifacts VirtualPITA (ESXi & Linux), VirtualPIE (ESXi), and VirtualGATE (Windows).

This malware differs in that it supports persistent and covert, which is consistent with the goals of larger threat actors and APT groups who target strategic institutions with the intention of dwelling undetected for some time, VMware said in a post.

Schneider Bold

This contrasts with other threat actors and their toolkits who conduct “noisy,” financially-motivated attacks using ransomware. Based on the indications this new malware was deployed post-compromise, VMware provided guidance on specific detection and mitigation techniques as well as preventative techniques for strengthening operational security, secure configuration practices, and defense-in-depth.

In terms of a mitigation, to prevent a potential compromise in the first place, VMware recommends enabling the Secureboot feature in ESXi to mitigate the risk of malicious actors persisting on a compromised ESXi host via malicious VIB installation. Secure boot was designed to disallow installation of unsigned VIBs on an ESXi host. In addition, secure boot disallows the –force flag which would normally allow an administrator to bypass acceptance level settings on the ESXi host.

To enable Secureboot perform the following steps:

  • Contact your hardware vendor for steps on how to enable UEFI/Secureboot for your system
  • To enable Secureboot on ESXi: UEFI Secure Boot for ESXi Hosts 
  • Run the Secure boot validation script: /usr/lib/vmware/secureboot/bin/secureBoot.py -c

Click here for more information on Protecting vSphere From Specialized Malware.

ISSSource

Pin It on Pinterest

Share This