<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci" -->

---
title: Unpatchable? How Chinese Hackers Hid in Dell VMs for 2...
description: CVE-2026-22769 (CVSS 10.0) exposes a critical flaw in Dell RecoverPoint for Virtual Machines appliances, exploited by Chinese state-sponsored group UNC6201 for...
canonical: https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Unpatchable? How Chinese Hackers Hid in Dell VMs for 2 Years Using &quot;Magic Packets&quot; | daily.dev
og:description: CVE-2026-22769 (CVSS 10.0) exposes a critical flaw in Dell RecoverPoint for Virtual Machines appliances, exploited by Chinese state-sponsored group UNC6201 for...
og:url: https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci
og:image: https://api.daily.dev/og/posts/FZVLV90ci.png
og:image:alt: Unpatchable? How Chinese Hackers Hid in Dell VMs for 2 Years Using &quot;Magic Packets&quot;
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Unpatchable? How Chinese Hackers Hid in Dell VMs for 2 Years Using "Magic Packets"

**[InfoSec Write-ups](https://daily.dev/sources/infosecwriteups)** · 7 min read · 29 upvotes · 0 comments

## Summary

CVE-2026-22769 (CVSS 10.0) exposes a critical flaw in Dell RecoverPoint for Virtual Machines appliances, exploited by Chinese state-sponsored group UNC6201 for nearly two years. The attack chain begins with hardcoded Apache Tomcat credentials, enabling deployment of the SLAYSTYLE web shell for root access. Attackers then pivot to advanced persistence techniques: 'Ghost NICs' (hot-plugged virtual network adapters bridged to separate VLANs to bypass firewalls) and 'Magic Packets' (Single Packet Authorization via iptables manipulation to hide backdoor ports from scanners). A new backdoor, GRIMBOLT, written in C# with Native AOT compilation, evades EDR tools by eliminating the JIT translation layer that security tools typically inspect. IOCs, remediation steps, and behavioral hunting queries are provided for defenders.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://infosecwriteups.com/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets-e5f8eb04e804>

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware), [#vulnerability](https://daily.dev/tags/vulnerability), [#vmware](https://daily.dev/tags/vmware)

[View this post on daily.dev](https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Unpatchable? How Chinese Hackers Hid in Dell VMs for 2 Years Using \"Magic Packets\"","url":"https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci"},"datePublished":"2026-02-19T05:45:32.783Z","dateModified":"2026-02-19T05:45:59.274Z","description":"CVE-2026-22769 (CVSS 10.0) exposes a critical flaw in Dell RecoverPoint for Virtual Machines appliances, exploited by Chinese state-sponsored group UNC6201 for...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8bff248f729c6172dddc0be03af29f7c?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8bff248f729c6172dddc0be03af29f7c?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"InfoSec Write-ups","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"InfoSec Write-ups","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/f0dc21b5bbfd46fda36f7b4b53dd1705","url":"https://daily.dev/sources/infosecwriteups"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":29},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,malware,vulnerability,vmware","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"InfoSec Write-ups","item":"https://daily.dev/sources/infosecwriteups"},{"@type":"ListItem","position":3,"name":"Unpatchable? How Chinese Hackers Hid in Dell VMs for 2 Years Using \"Magic Packets\""}]}
```

