Forwarded message: > From: Monty Solomon <[email protected]> > To: Richard Forno <[email protected]> > Subject: Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within > ESXi Hypervisors > Date: Thu, 29 Sep 2022 10:35:18 -0400 > > Earlier this year, Mandiant identified a novel malware ecosystem impacting > VMware ESXi, Linux vCenter servers, and Windows virtual machines that enables > a threat actor to take the following actions: > > Maintain persistent administrative access to the hypervisor > Send commands to the hypervisor that will be routed to the guest VM for > execution > Transfer files between the ESXi hypervisor and guest machines running beneath > it > Tamper with logging services on the hypervisor > Execute arbitrary commands from one guest VM to another guest VM running on > the same hypervisor > > https://www.mandiant.com/resources/blog/esxi-hypervisors-malware-persistence -- Iw mailing list [email protected] http://sticklist.org/mailman/listinfo/iw_sticklist.org
