Chinese Spies Exploited Critical VMware Bug for Nearly 2 Years
ID: 3fd783ad-67a3-54c4-987c-8bde76409397
STIX ID: report--3fd783ad-67a3-54c4-987c-8bde76409397
Feed Name: Dark Reading
Threat Score
Mandiant revealed that Chinese APT UNC3886 exploited VMware vCenter vulnerability CVE-2023-34048 (CVSS 9.8) as a zero-day since at least late 2021 to gain RCE, trigger VMware Directory Service crashes as a canary, deploy backdoors ('VirtualPita' and 'VirtualPie'), steal credentials, and subsequently compromise ESXi hosts; organizations should confirm patches and investigate possible infections per VMware's advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
