logo

Chinese hackers exploit VMware bug as zero-day for two years

ID: 613ea341-22a5-5254-849f-bce9073d1b46

STIX ID: report--613ea341-22a5-5254-849f-bce9073d1b46

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-01-19

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Mandiant attributes a long-running Chinese APT (UNC3886) campaign to exploitation of a VMware vCenter zero-day (CVE-2023-34048) since at least late 2021 to breach vCenter servers, deploy VirtualPita/VirtualPie backdoors on ESXi via malicious VIBs, and leverage a VMware Tools authentication bypass (CVE-2023-20867) to escalate privileges and exfiltrate data; the actor also exploited a Fortinet zero-day (CVE-2022-41328) to install Castletap and Thincrust implants, demonstrating sophisticated, targeted espionage against high-value sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.