logo

Chinese Hackers Silently Weaponized VMware Zero-Day Flaw for 2 Years

ID: 0ad18790-e1fc-58c2-b298-a2b65bc8aac2

STIX ID: report--0ad18790-e1fc-58c2-b298-a2b65bc8aac2

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-01-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

UNC3886, a China-linked advanced threat actor, has been attributed with weaponizing VMware vCenter Server zero-day CVE-2023-34048 (CVSS 9.8) to obtain privileged access, enumerate ESXi hosts, retrieve vpxuser credentials, and deploy VIRTUALPITA/VIRTUALPIE implants to compromised hosts and guest VMs; the actor also previously exploited Fortinet CVE-2022-41328 to deploy THINCRUST and CASTLETAP. Mandiant reported these activities, VMware acknowledged in-the-wild exploitation and released patches — organizations using vCenter and affected Fortinet products are advised to apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.