Esxi Exploitation In The Wild
TL;DR: Huntress documented a december 2025 intrusion where attackers deployed an esxi vm-escape toolkit after likely initial access via a…
Esxi Exploitation In The Wild
TL;DR: Huntress documented a december 2025 intrusion where attackers deployed an esxi vm-escape toolkit after likely initial access via a compromised sonicwall vpn; the toolkit targets 155 esxi builds (5.1–8.0) and uses kdu to load unsigned drivers and disable vmci.
Context The Huntress incident involves lateral movement using a compromised Domain Admin account and deployment of specialized tooling aimed at breaking out of guest VMs to the ESXi hypervisor. The report highlights both host-level and network-level detection gaps exposed during the intrusion.
What’s New The toolkit analyzed by Huntress contains Simplified Chinese development paths (notably a folder named “全版本逃逸 — 交付”) and appears to have been developed well before public disclosure of the underlying vulnerability. It supports 155 ESXi builds across versions 5.1 through 8.0, indicating broad targeting and a well-resourced developer.
Technical Breakdown Observed artifacts include Advanced_Port_Scanner_2.5.3869.exe, SoftPerfect netscan.exe, ShareFinder output saved to C:\ProgramData\shares.txt, devcon-based disabling of VMCI devices, and use of Kernel Driver Utility (KDU) to load an unsigned driver. The adversary staged data for exfiltration using WinRAR archive commands. An attempted Domain Admin password change via Impacket was blocked by managed Microsoft Defender for Endpoint. The report notes that VSOCK traffic between VMs and the hypervisor is often invisible to perimeter controls, complicating network-based detection.
Detection & Mitigation Huntress recommends host-level visibility on ESXi hosts to detect unusual processes and file handles; the investigation cited lsof -a for identifying open files on hosts. Monitoring for unexpected driver loads and devcon-driven device state changes on Windows systems is also highlighted. Patching ESXi is emphasized where fixes are available; end-of-life versions lack official fixes and remain exposed.
Limitations Attribution remains limited to indicators in development paths and workstation artifacts; no public CVE mapping was provided in the report. Some detection techniques are constrained by invisible VSOCK channels that bypass typical network sensors.
vmware #esxi #kdu #vmci #threatintel
SOURCE: https://www.huntress.com/blog/esxi-vm-escape-exploit

메타데이터
- post_id
- 787b2859a45f
- slug
- esxi-exploitation-in-the-wild-787b2859a45f
- url
- https://medium.com/@hasamba/esxi-exploitation-in-the-wild-787b2859a45f
- canonical_url
- https://medium.com/@hasamba/esxi-exploitation-in-the-wild-787b2859a45f
- author_url
- https://medium.com/@hasamba
- status
- ok
- fetched_at
- 2026-06-14 11:28:49