{"id":11431,"date":"2025-07-25T12:21:22","date_gmt":"2025-07-25T05:21:22","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11431"},"modified":"2026-06-25T09:59:01","modified_gmt":"2026-06-25T02:59:01","slug":"hacker-group-fire-ant-exploits-vmware-vulnerabilities-to-attack-esxi-and-vcenter-environments","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/25\/hacker-group-fire-ant-exploits-vmware-vulnerabilities-to-attack-esxi-and-vcenter-environments\/","title":{"rendered":"hacker group Fire Ant exploits VMware vulnerabilities to attack ESXi and vCenter environments"},"content":{"rendered":"<div style=\"text-align: justify\"><b>A highly sophisticated and silent cyber espionage campaign has been found to be targeting the key virtualization infrastructure and networking equipment. The attack group known as &#8220;Fire Ant&#8221;, believed to be related to UNC3886 (the hacker group associated with China) has silently infiltrated systems using VMware ESXi and vCenter Server, two core components in modern virtualization infrastructures.<\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/vmware-vcentre-png.17369\/\" target=\"_blank\" rel=\"noopener\" data-caption=\"&lt;h4&gt;Vmware Vcentre.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;nhom-hacker-fire-ant-khai-thac-lo-hong-vmware-tan-cong-esxi-va-moi-truong-vcenter.18602&amp;#x2F;#post-44111&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 25&amp;#x2F;07&amp;#x2F;2025 l\u00fac 4:08 PM&lt;\/a&gt;&lt;\/p&gt;\" data-fancybox=\"lb-thread-18602\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"Vmware Vcentre.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/17\/17704-38d7dd3c8459c24d0b5322d20d5db45a.jpg\" alt=\"Vmware Vcentre.png\" width=\"712\" height=\"400\" \/><\/a>\u200b<\/div>\n<div style=\"text-align: justify\">\n<p>Fire Ant is the provisional designation for the hacker group allegedly associated with UNC3886. What the two groups have in common is that they both use the same tools and techniques, targeting assets that are outside the safeguards of traditional security software.<\/p>\n<p>The attack is not only intended to steal information but can also cause complete loss of control over the system, especially critical systems that are being &#8220;lost&#8221; in the current security strategy.<\/p>\n<p>Fire Ant focuses its attack on:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">VMware ESXi and vCenter Server (virtual machine management system)<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Network devices such as F5 load balancers<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Environments that are said to be &#8220;isolated&#8221;, not connected to public networks<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">These systems often have little security scrutiny, few monitoring logs, and often no antivirus software.<br \/>\nHoles exploited:<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">CVE-2023-34048: Vulnerabilities in VMware vCenter Server, allowing remote access.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">CVE &#8211; 2023-20867: Vulnerabilities in VMware Tools, which allow direct interference with the running virtual machine.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>Notably, UNC3886 had been exploiting CVE -2023-34048 since it was a zero &#8211; day vulnerability, before being patched by Broadcom in October 202 3.<\/p>\n<p>Fire Ant uses a kill chain with complex techniques:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">A persistent backdoor (the &#8220;VIRTUALPITA&#8221; type) into both ESXi and vCenter, persisting through system restarts.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Use a Python implant to execute remote commands and send\/receive files.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">exploit VMware Tools vulnerability to manipulate virtual machines from hypervisor.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Blocking and deletion of system logs by turning off the vmsyslogd logging service, making post-attack monitoring and analysis meaningless.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Create unregistered fake virtual machine to avoid detection.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Create a network tunnel (V2Ray) to bypass network segmentation barriers and maintain access.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">Extent of influence and consequences<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">The attacks are taking place globally, not just in the Asia &#8211; Pacific region.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Targets are organizations operating important infrastructure, which have strategic economic and security value.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Singapore has recently formally accused UNC3886 of being involved in attacks on national critical infrastructure, affecting essential services.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Potential risk: The hacker may have access to the entire internal network, overcoming any barriers if a single vulnerability is exploited.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>Fire Ant&#8217;s campaign was a serious wake-up call to the vulnerability of current security thinking itself, as critical infrastructure and network equipment were neglected in incident detection and response strategies. Focusing on the endpoint is no longer sufficient.<\/p>\n<p>Security solutions recommended by experts:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Immediately update all security patches for VMware vCenter, ESXi, and Vmware Tools.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Monitor and collect the full log for the virtualization system &#8211; do not leave the log empty or not recorded.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Implement security monitoring in the hypervisor visibility layer, using specialized solutions if necessary.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Check and track privileged accounts such as pxuser.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Re-evaluate network segmentation, restrict access between sensitive network areas.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Increase testing for new virtual machines, prevent unchecked implementations of unknown machines.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">Operation Fire Ant showed a new generation of attacks emerged, focusing on less-noticed infrastructure layers, superior technical use, and long-term silent operations. Security today is no longer a matter of &#8220;virtual anti-retrovirus&#8221; but rather a contest between systems understanding and the ability to detect aberrant behavior.<\/div>\n<div style=\"text-align: right\"><b><i>WhiteHat, The Hacker News<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/nhom-hacker-fire-ant-khai-thac-lo-hong-vmware-tan-cong-esxi-va-moi-truong-vcenter.18602\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/nhom-hacker-fire-ant-khai-thac-lo-hong-vmware-tan-cong-esxi-va-moi-truong-vcenter.18602\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A highly sophisticated and silent cyber espionage campaign has been found to be targeting the key virtualization infrastructure and networking equipment. The attack group known as &#8220;Fire Ant&#8221;, believed to be related to UNC3886 (the hacker group associated with China) has silently infiltrated systems using VMware ESXi and vCenter Server, two core components in modern [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11431","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11431","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11431"}],"version-history":[{"count":2,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11431\/revisions"}],"predecessor-version":[{"id":11645,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11431\/revisions\/11645"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11431"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11431"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11431"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}