A fireant
– Getty Images

A stealthy Chinese cyberespionage campaign dubbed "Fire Ant" has been targeting virtualization and network infrastructure, including VMware ESXi, vCenter servers, and F5 load balancers.

According to a report by cybersecurity firm Sygnia, the group demonstrated a “high degree of persistence and operational maneuverability,” exploiting various methods to infiltrate restricted and segmented network environments.

The hackers exploited multiple vulnerabilities, including:

CVE-2023-34048 – a vCenter bug that allows unauthenticated remote code execution.

CVE-2023-20867 – a flaw in VMware Tools that enables command execution in guest virtual machines (VMs) from the hypervisor without requiring authentication.

CVE-2022-1388 – a vulnerability in F5 load balancers' iControlREST API, used for unauthenticated remote access.

Fire Ant’s infiltration method focuses on initial access by compromising network appliances.

Once inside, the group usedsa mix of hypervisor-level and network-layer techniques to stay there, including bypassing authentication using host-to-guest command injections (executing commands from a hypervisor like ESXi directly into VMs without authentication).

Sygnia suggests the espionage operation showed a deep understanding of enterprise infrastructure, with the hackers able to quickly recompromise systems using redundant access paths once defenders removed backdoors or blocked access.

The hackers even renamed binaries to mimic forensic tools and observed blue team activity to avoid detection.

Sygnia also discovered that Fire Ant utilized methods similar to other Chinese cyberespionage groups, such as UNC3886, which was responsible for last year's attack on Juniper Networks' Junos OS routers.

“The activity uncovered in Fire Ant’s campaign underscores the urgent need to both harden and monitor virtualization infrastructure,” Sygnia wrote in a blog post. “Traditional security controls often overlook ESXi, vCenter, and related components, leaving critical gaps in visibility and response. Defenders must treat these systems as part of the active threat surface and ensure they are monitored and protected.”

Patch gaps may leave VMware users at risk

Fire Ant marks the latest in a growing number of campaigns targeting networking devices. In June, another Chinese-linked effort, dubbed "LapDogs," was found to have stealthily infiltrated more than 1,000 Linux and Windows-based systems since at least September 2023.

With this latest campaign targeting VMware environments, it may leave some of its customers potentially exposed amid claims from some users that they’ve been unable to download security patches.

Following changes to VMware rules following Broadcom’s acquisition, holders of perpetual licenses who fail to take up support contracts receive only the bare minimum of support once their maintenance agreements expire.

However, recent reports claim some customers have been unable to access software patches. One user, who claimed they’ve been unable to access updates since May, reached out to Broadcom support staff, who replied: “Recent changes to our support portal, related to entitlement checking, will cause [a] delay in making patches available to customers with expired entitlements.”

Last April, Broadcom CEO Hock Tan said that users would have “free access to zero-day security patches for supported versions of vSphere” with other VMware products to be added over time.

Nothing has changed in Broadcom's commitment regarding critical VMware security patches," a Broadcom spokesperson said in a statement provided to SDxCentral. "Users of legacy VMware products who no longer have active maintenance and support entitlements will have free access to critical security patches for as long as those products remain supported by Broadcom.

"This includes the patches for critical vulnerabilities addressed in VMware Security Advisory 2025-0013. Because our support portal requires validation of customer entitlements for software patches, only entitled customers have access to the patches at this time. A separate patch delivery cycle will also be available for non-entitled customers and will follow at a later date.”