ESXi ALERT: Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors
This malware ecosystem was initially detected during an intrusion investigation when Mandiant identified attacker commands sourced from the legitimate VMware Tools process, vmtoolsd.exe, on a Windows virtual machine hosted on a VMware ESXi hypervisor.