Security1 distinct publisher2 min readPublished
Sygnia says the actor pivoted from vCenter into ESXi on stolen vpxuser credentials, left backdoors that survive reboots, and terminated vmsyslogd so the hosts stopped writing an audit trail while containment ran.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
vpxuser is the account vCenter keeps so it can log in to the ESXi hosts it manages. That step in the chain was pure credential reuse, not an exploit or malware: the management server already holds the credential it needs to do its job [6]. The exploit was upstream, in CVE-2023-34048 on vCenter Server itself [4].
What lands after that is chosen for where the sensors are not. Sygnia found backdoors on both vCenter and the hosts, persistent across reboots, matched to the VIRTUALPITA family by filename, hash and deployment technique [7], plus a Python daemon called autobackup.bin running in the background for remote command execution and file transfer [8]. V2Ray handled tunneling into guest networks [17]. Credentials came out of memory snapshots, domain controllers among them [10]. Sygnia's own read is that the hypervisor and infrastructure layer is where traditional endpoint tooling is ineffective [13].
The response phase got worked on too. Virtual machines were deployed unregistered on multiple hosts, so the management plane held no record of them [12], and payloads were renamed to impersonate forensic tools, which defeats the responder scanning a process list for something that looks wrong [15]. Sygnia says the actor re-compromised assets, switched tooling, dropped fallback backdoors and altered network configurations while containment was under way [3][15]. Eradication on this layer only works if it happens simultaneously across vCenter, the hosts and the appliances, because sequential cleanup reopens the ingress that was just closed.
Two dates carry more weight than the tradecraft. Broadcom patched CVE-2023-34048 in October 2023 [5], and Sygnia published this activity in July 2025, 21 months later [16][1]. The segmentation break used CVE-2022-1388 against F5 load balancers, with web shells left for cross-segment persistence [14], and the guest interaction used CVE-2023-20867 in VMware Tools [9]. All three identifiers are from 2022 and 2023 [2]. Nothing in the chain needed a fresh zero-day in 2025. It needed infrastructure that stays unrebooted and unpatched for long stretches, with little monitoring in place.
On attribution, Sygnia describes shared tooling and targeting with UNC3886, the China-nexus group that has been working edge devices and virtualization since at least 2022, as an overlap rather than an identification [2]. Whether the operators are the same is unresolved in the report. What is settled is the objective: the hypervisor is the target in its own right [1].
Ranked by verification strength, evidence, and original report placement.
Fire Ant is assessed to share tooling and targeting overlaps with prior campaigns by UNC3886, a China-nexus cyber espionage group known for persistent targeting of edge devices and virtualization technologies since at least 2022.
Sygnia reported a prolonged cyber espionage campaign by an actor it codenames Fire Ant, primarily designed to infiltrate organizations' VMware ESXi and vCenter environments as well as network appliances.
Sygnia said the attacker operated through eradication efforts, adapting in real time to eradication and containment actions, switching to different tools, dropping fallback backdoors for persistence, and altering network configurations to re-establish access.
Fire Ant's breach of the virtualization management layer was achieved by exploiting CVE-2023-34048, a flaw in VMware vCenter Server.
CVE-2023-34048 was exploited by UNC3886 as a zero-day for years prior to being patched by Broadcom in October 2023.
Sygnia said that from vCenter the actor extracted the vpxuser service account credentials and used them to access connected ESXi hosts.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
One console, two businesses: Broadcom says Jewelbug runs espionage and crypto fraud together1 distinct publisher
product
Nutanix's $2.55B ARR says the VMware exodus still pays, on someone else's server lead times1 distinct publisher
build
Fire Ant manipulated router show outputs and syslogs while running rare GRE tunnels, report finds1 distinct publisher
security
Silent patches ship the details anyway. Only the defenders miss them1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor's case notes, unusually specific
Filenames, a killed daemon, a service account, three CVEs — the detail is granular enough to hunt with, and all of it traces to Sygnia's own engagements as relayed by The Hacker News. Nothing has been independently examined: no victim is identified, no indicator set is published, and the only externally checkable anchors are Broadcom's October 2023 patch and Trend Micro's separate catalogue of UNC3886 tooling.
Real intrusions, undisclosed footprint
This is not a product with users; the traction question is how many estates were entered, and the answer is withheld. Sygnia says multiple ESXi hosts and refers to responding on the ground, but names no organisation, sector or region. Singapore's attribution of related activity to UNC3886 and Trend Micro's follow-up suggest the tradecraft is not confined to one vendor's caseload — nobody supplies a count.
The framing outruns the facts by a little
The prose is restrained and the tradecraft genuinely nasty; the tilt sits in the omissions. An actor who entered through a vCenter flaw patched in October 2023, pivoted with a VMware Tools bug from the same year, and crossed segments through a 2022 F5 vulnerability was partly walking through doors that had fixes available well before the intrusions — and this reporting never says whether the victims had applied them. "Outlasted eradication" is accurate about the response; it quietly flatters the sophistication of the entry.
The conclusion is also the product
Sygnia ends where its service begins: the hypervisor layer lacks detection and endpoint tools are ineffective there. That may well be true, and it is still a sales argument, with Trend Micro publishing into the same market days later. On attribution, Singapore's minister and the Chinese embassy's rebuttal are both interested parties. A reader gets no disinterested account of what happened in these environments.
Enough to act on, not enough to verify
Internally the account holds together and the checkable parts check out, so hardening vpxuser, protecting host logging and auditing for unregistered VMs are defensible moves on this basis alone. But a single outlet relaying a single responder leaves no way to test the campaign's scope, and the reporting reaches us long after its July 2025 publication, so what has changed since is unknown.