By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
Notification Show More
Latest News
Why a tiny American firm is taking aim at an Indian conglomerate
Uncategorized
‘It turned bad in an instant’: CNN crew has close call in Ukraine as Russian missiles pummel their location
Uncategorized
Offices are more than 50% filled for the first time since the pandemic started
Uncategorized
There’s a sense that another turning point is approaching in Russia’s war in Ukraine
Uncategorized
Russia Pushes to Take Ukrainian Town Near a Vital Supply Line
Sports
Aa
  • Home
  • Politics
  • Business
  • LifeStyle
  • Sports
  • Entertainment
  • Health
  • Tech
Reading: VMware virtualization software is being hijacked to spy on businesses
Share
Aa
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
  • ES Money
  • U.K News
  • Entertainment
  • Science
  • Technology
  • Insider
Search
  • Home
  • Politics
  • Business
  • Sports
  • Entertainment
  • Health
  • Life Style
  • Tech
Have an existing account? Sign In
Follow US
Confluence News - Breaking News, Latest News and Videos > Blog > Tech > VMware virtualization software is being hijacked to spy on businesses
Tech

VMware virtualization software is being hijacked to spy on businesses

Last updated: 2022/09/30 at 1:53 PM
Share
SHARE

Criminals have managed to compromise VMware’s ESXi hypervisors and gain access to countless virtual machines, meaning they can spy on numerous businesses using the hardware without those businesses ever knowing they’re being spied upon.

The warning was given out by cyber threat intelligence firm Mandiant, together with virtualization firm VMware. 

According to the two companies, unknown threat actors with possible ties to China, installed two malicious programs on bare-metal hypervisors, using vSphere Installation Bundles. They named them VirtualPita and VirtualPie (“Pita” also means “pie” in some Slavic languages). Furthermore, they discovered a unique malware/dropper dubbed VirtualGate.

No vulnerability

What’s important to note is that the attackers did not find a zero-day, or exploit a different, known vulnerability. Instead, they used admin-level access to the ESXi hypervisors to install their tools. 

Speaking to WIRED, VMware said that “while there is no VMware vulnerability involved, we are highlighting the need for strong operational security practices that include secure credential management and network security.”

VMware also said it prepared a “hardening” guide for VMware setup admins, that should help them protect against this type of attack. 

Read more

> Is it time to give KVM hypervisor a go?

> Citrix confirms its VM software will run Windows 11, eventually

> We’ve rounded up the best virtual desktop services around

The threat actor is tracked as UNC3886. The researchers are saying that while it does show some signs of being a Chinese-based group (the victims are the same as for some other Chinese groups; there are certain similarities in the malware code and other known malicious programs), they can’t confirm, with absolute certainty, that that is the case. 

The attack allows the threat actors to maintain persistent admin access to the hypervisor, send commands to the endpoint that will be routed to the guest VM for execution, steal files between the ESXi hypervisor and guest machines running underneath it, make changes to the logging services on the hypervisor, and execute arbitrary commands from one guest VM to another guest VM, as long as they’re on the same hypervisor.

Check out the best firewalls around

Via: Wired

 

You Might Also Like

The company behind DeepTomCruise is bringing its de-aging tech to Hollywood

How Disney’s Dreamlight Valley Made Me Feel Like A Kid Again

Battery leak reveals more about Samsung’s new XR headset

Your smart speaker could be listening to more than you think

September 30, 2022
Share this Article
Facebook Twitter Email Print
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Social Medias
Facebook Like
Twitter Follow
Youtube Subscribe
Telegram Follow

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

[mc4wp_form]
Popular News
Tech

One of Xbox Series X’s standout features could soon have an off switch

October 6, 2022
Government homes in on £5bn cladding settlement with housebuilders
Google Chrome ad blockers live on after API changes postponed
QB Rodgers: ‘Time to go all grass’ on NFL fields www.espn.com – TOP
Women’s Super League: talking points from the weekend’s action Football The Guardian
- Advertisement -
Ad imageAd image
Global Coronavirus Cases

Confirmed

0

Death

0

More Information:Covid-19 Statistics

Categories

  • ES Money
  • Insider
  • Science
  • Technology
  • LifeStyle

About US

We influence 20 million users and is the number one business and technology news network on the planet.
Quick Link
  • Economy
  • Politics
  • Life Style
  • Contact Us
Top Categories
  • Business
  • Tech
  • Top
  • Health
  • Entertainment

Subscribe US

Subscribe to our newsletter to get our newest articles instantly!

© confluencenews. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?