A new Python backdoor targeting VMware ESXi servers was detected, allowing hackers to execute remote commands on a compromised system.
See also: 2022: Ethical hackers discovered 65,000 vulnerabilities

VMware ESXi is a virtualization platform commonly used by businesses to host multiple servers on a single device, while using CPU and memory more efficiently.
Juniper Networks researchers recently discovered the backdoor on a VMware ESXi server, but unfortunately they were unable to identify the root cause of the compromise, given the limited retention of log files.
They believe the server may have been breached using the CVE-2019-5544 and CVE-2020-3992 vulnerabilities in the ESXi OpenSLP service.
Although the malware can theoretically target Linux and Unix systems, Juniper analysts observed several indications that created to attack ESXi.
See also: Australia: 4 Arrests for Pig Butchering scam worth 100 million
Operation of the backdoor
The new python backdoor adds seven lines inside “/etc/rc.local.d/local.sh”, one of the few ESXi files that survives between reboots and is executed at boot.
Normally, this file is empty except for a few comments and an exit statement.

One of these lines launches a Python script stored as “/store/packages/vmtools.py,” in a directory that stores VM disk images, logs and other.
Juniper Networks assumed that the malware's administrators had a clear goal of specifically targeting VMware ESXi servers, given the name and location.
According to the Juniper Networks report, the Python script used in this attack is quite flexible so that it can be adapted for use with Linux and other UNIX-type systems without requiring significant modifications. Nevertheless, there are numerous indicators that this malicious code was specifically designed to target ESXi machines.
This script starts a web server that accepts encrypted POST requests from external sources. These requests may contain commands or launch a reverse shell on the host.
See also: Azov Wiper: New dangerous wiper malware appears
The reverse shell technique allows the malicious actor to bypass firewall restrictions and limited network connectivity.
Juniper security experts have identified malicious actors modifying ESXi's HTTP proxy configuration to provide remote access and communicate with a "planted" webserver.
Because the file used to set up this new configuration, “/etc/vmware/rhttpproxy/endpoints.conf”, is both backed up and restored after reboot, any modifications to it are persistent.

To assess whether your ESXi servers have been affected by this backdoor, look for the aforementioned files as well as any added lines in the “local.sh” file.
To ensure the highest level of security, all configuration files that persist across reboots must be examined carefully for any signs of suspicious modifications and restored immediately to the appropriate settings.
Finally, admins should restrict all incoming network connections to trusted hosts, and available security updates that address exploits used for initial compromise should be applied as soon as possible.
Information source: bleepingcomputer.com
