logo

Chinese Spies Exploited Critical VMware Bug for Nearly 2 Years

ID: 3fd783ad-67a3-54c4-987c-8bde76409397

STIX ID: report--3fd783ad-67a3-54c4-987c-8bde76409397

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-01-22

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Mandiant revealed that Chinese APT UNC3886 exploited VMware vCenter vulnerability CVE-2023-34048 (CVSS 9.8) as a zero-day since at least late 2021 to gain RCE, trigger VMware Directory Service crashes as a canary, deploy backdoors ('VirtualPita' and 'VirtualPie'), steal credentials, and subsequently compromise ESXi hosts; organizations should confirm patches and investigate possible infections per VMware's advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.