Hackers Employ Linux Rootkits to Conceal Themselves on VMware ESXi Virtual Machines in UNC3886
A Chinese threat actor known as UNC3886 has been using open source rootkits Reptile and Medusa to hide on VMware ESXi virtual machines while stealing credentials and executing commands. Mandiant has been tracking UNC3886’s activities against government organizations, including attacks exploiting zero-day vulnerabilities in Fortinet and VMware products. UNC3886 has recently targeted organizations in North … Read more