UNC3886 hackers use Linux rootkits to hide on VMware ESXi VMs
ID: e4f4e323-6bda-5bdd-bdf5-e135a61657ed
STIX ID: report--e4f4e323-6bda-5bdd-bdf5-e135a61657ed
Feed Name: Bleeping Computer
Mandiant reports that UNC3886, a suspected Chinese-affiliated threat actor, exploited VMware ESXi and other zero-days to implant open-source rootkits (REPTILE, MEDUSA) and custom backdoors (Mopsled, Riflespine, VMCI families) across governments and critical industries worldwide, using those implants for stealthy persistence, credential theft, command execution, lateral movement, and C2 via public services; the report includes observed customizations, victim geography and sectors, and links to IoCs and YARA rules for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
