Article Details

Scrape Timestamp (UTC): 2025-07-24 17:13:08.866

Source: https://thehackernews.com/2025/07/fire-ant-exploits-vmware-flaw-to.html

Original Article Text

Click to Toggle View

Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments. Virtualization and networking infrastructure have been targeted by a threat actor codenamed Fire Ant as part of a prolonged cyber espionage campaign. The activity is primarily designed to infiltrate organizations' VMware ESXi and vCenter environments as well as network appliances, Sygnia said in a new report published today. "The threat actor leveraged combinations of sophisticated and stealthy techniques creating multilayered attack kill chains to facilitate access to restricted and segmented network assets within presumed to be isolated environments," the cybersecurity company said. "The attacker demonstrated a high degree of persistence and operational maneuverability, operating through eradication efforts, adapting in real time to eradication and containment actions to maintain access to the compromise infrastructure." Fire Ant is assessed to share tooling and targeting overlaps with prior campaigns orchestrated by UNC3886, a China-nexus cyber espionage group known for its persistent targeting of edge devices and virtualization technologies since at least 2022. Attacks mounted by the threat actor have been found to establish entrenched control of VMware ESXi hosts and vCenter servers, demonstrating advanced capabilities to pivot into guest environments and bypass network segmentation by compromising network appliances. Another noteworthy aspect is the ability of the threat actor to maintain operational resilience by adapting to containment efforts, switching to different tools, dropping fallback backdoors for persistence, and altering network configurations to re-establish access to compromised networks. Fire Ant's breach of the virtualization management layer is achieved by the exploitation of CVE-2023-34048, a known security flaw in VMware vCenter Server that has been exploited by UNC3886 as a zero-day for years prior to it being patched by Broadcom in October 2023. "From vCenter, they extracted the 'vpxuser' service account credentials and used them to access connected ESXi hosts," Sygnia noted. "They deployed multiple persistent backdoors on both ESXi hosts and the vCenter to maintain access across reboots. The backdoor filename, hash and deployment technique aligned the VIRTUALPITA malware family." Also dropped is a Python-based implant ("autobackup.bin") that provides remote command execution, and file download and upload capabilities. It runs in the background as a daemon. Upon gaining unauthorized access to the hypervisor, the attackers are said to have leveraged another flaw in VMware Tools (CVE-2023-20867) to interact directly with guest virtual machines via PowerCLI, as well as interfered with the functioning of security tools and extracted credentials from memory snapshots, including that of domain controllers. Some of the other crucial aspects of the threat actor's tradecraft are as follows - The attack chain ultimately opened up a pathway for Fire Ant to maintain persistent, covert access from the hypervisor to guest operating systems. Sygnia also described the adversary as possessing a "deep understanding" of the target environment's network architecture and policies in order to reach otherwise isolated assets. Fire Ant is unusually focused on remaining undetected and leaves a minimal intrusion footprint. This is evidenced in the steps taken by the attackers to tamper with logging on ESXi hosts by terminating the "vmsyslogd" process, effectively suppressing an audit trail and limiting forensic visibility. The findings underscore a worrying trend involving the persistent and successful targeting of network edge devices by threat actors, particularly those from China, in recent years. "This campaign underscores the importance of visibility and detection within the hypervisor and infrastructure layer, where traditional endpoint security tools are ineffective," Sygnia said. "Fire Ant consistently targeted infrastructure systems such as ESXi hosts, vCenter servers, and F5 load balancers. The targeted systems are rarely integrated into standard detection and response programs. These assets lack detection and response solutions and generate limited telemetry, making them ideal long-term footholds for stealthy operation."

Daily Brief Summary

NATION STATE ACTIVITY // Fire Ant Espionage Campaign Exploits VMware to Infiltrate Networks

Fire Ant, a cyber espionage group with links to China-linked UNC3886, has been targeting virtualization technologies, specifically VMware ESXi and vCenter servers.

The campaign involves sophisticated, multilayered attack techniques aimed at gaining and maintaining access to virtually segmented network environments.

The attackers have demonstrated high persistence and adaptability, continuously modifying tactics and tools to circumvent eradication efforts and maintain control.

Utilization of known vulnerabilities such as CVE-2023-34048 in VMware vCenter Server and CVE-2023-20867 in VMware Tools to manipulate network environments and extract critical credentials.

Deployment of persistent backdoors and usage of Python-based malware providing remote command execution to keep access through reboot cycles.

Direct interaction with guest VMs via stolen credentials and the manipulation of security measures to ensure stealth and uninterrupted access.

Significant concern highlighted by Sygnia regarding the lack of visibility and effective detection methods at the hypervisor and infrastructure layers, where traditional security tools fall short.