Installing Kali Linux on VirtualBox is fastest with the pre-built image from Kali’s own site, which skips the ISO installer entirely. Download the image, check its checksum, and set the VirtualBox options that make the machine boot.
What You Need Before the Download
The image is the same on Windows, macOS, and Linux hosts, but four things decide whether the virtual machine boots when you press Start.
| Check | Why it decides the outcome |
|---|---|
| 64-bit host with VT-x or AMD-V | VirtualBox asks the CPU for hardware virtualization, and Kali will not start without it |
| VirtualBox 7.2.16 or later | That is the current Oracle release, and it opens the .vbox file the image ships |
| About 20 GB of free disk | A 3.7 GiB archive and a 16 GB virtual disk that unpacks next to it |
| 4 GB of RAM or more | The machine definition asks for 2048 MB, which is tight once you open Wireshark |
Download the Image and Check the Checksum
On the Kali download page, the Virtual Machines section holds the VirtualBox build under the name kali-linux-2026.2-virtualbox-amd64.7z, and the current file is 3,922,416,160 bytes. If your connection drops on large files, the .torrent sitting beside it is the safer download because it can resume and repair itself.
Check the file before you spend disk on it. The published SHA256SUMS list carries both lines below, and the second one is the file you just downloaded.
41ed7ec51cdd3a5ca663ec09492261ba81acb26625fdda85ce7acb16909f3cee kali-linux-2026.2-virtualbox-amd64.7z
736b1ce83419335dd7a013c2f9a15c683fffb29735bfbb48fa8c6a8f9b0894cb kali-linux-2026.2-virtualbox-amd64.7z.torrent
Run the hash on your copy and compare the two strings by eye or with a diff. I ran it on the 3.7 GiB file and got the same line Kali publishes.
curl -s https://cdimage.kali.org/current/SHA256SUMS | grep virtualbox-amd64.7z
sha256sum kali-linux-2026.2-virtualbox-amd64.7z
A truncated download normally dies at the very end of extraction, after the whole 16 GB has unpacked. The checksum catches it in about a minute instead.

Extract the Archive
Kali ships the VirtualBox build as a 7z archive with exactly two entries, and both live in one solid LZMA2 block. That is why you cannot pull out the small machine definition on its own, because the compressor treats the pair as a single stream, so the whole archive comes out or nothing does.
7z x kali-linux-2026.2-virtualbox-amd64.7z
Windows users need the official 7-Zip app, and Debian or Ubuntu hosts need p7zip-full. Both write a folder named after the archive, and the folder holds the machine definition and the disk.
| File | Size | What it is |
|---|---|---|
| kali-linux-2026.2-virtualbox-amd64.vbox | 3 KB | Plain XML that names the machine and points at the disk |
| kali-linux-2026.2-virtualbox-amd64.vdi | 16 GB | The virtual hard disk Kali boots from |
I listed the archive before extracting it, so the 3 KB machine definition next to a 16 GB disk was no surprise, and I checked the extracted sizes once the folder was complete. Here is the same folder once the archive is unpacked.

On a Linux host, extracting 7z files from the terminal covers the package install and the same command used here. Keep the archive until the VM boots at least once, because the extraction is the step that fails when a download is damaged.
Add the Machine to VirtualBox
Open VirtualBox, go to the Machine menu, and choose Add. Navigate to the extracted folder and select the .vbox file. There is no Import Appliance dialog in this path, and the file picker will not offer the archive, because a 7z is not something VirtualBox can read.
The .vbox is 3 KB of XML, which sounds too small to be a computer. It is a machine definition rather than a disk, so it names the VM, records the hardware it expects, and stores the disk as a reference to the .vdi sitting beside it.

That reference is why the machine definition and the disk have to travel together. Move the .vbox on its own and VirtualBox opens a machine whose hard disk is missing.
Before the first boot, open Settings and compare what the machine definition declares: 2048 MB of RAM, 2 CPUs, a Debian 64-bit type, and bidirectional clipboard and drag and drop. I opened the extracted .vbox to read those values straight from the XML, and they are the ones you will see in Settings. Raise the memory if your host has room, because 2048 MB is a floor the heavier tools will push against.
A snapshot taken now costs a few gigabytes and saves you a rebuild later. Backing up a VirtualBox machine covers snapshots and exports, and the same menu holds both. If you would rather compare virtualization tools first, installing CentOS with VirtualBox on Windows walks the same host setup with a different guest.
First Boot and Login
Select the machine and press Start. The guest boots to the Kali login screen, and the credentials are kali for the user and kali for the password, which every install guide publishes because the image cannot ship with a secret.

Change that password on the first login, because a machine with kali as its password is a machine anyone on your network can reach. The passwd command handles it in one line.
passwd
What you land on is a full Xfce desktop with the toolset already installed, not a bare system waiting for setup.

Shared clipboard and drag and drop work from the first boot as well, because the machine definition sets both to bidirectional. Kali’s documentation confirms the guest tools are in the image: virtualbox-guest-x11 is installed during setup automatically and ships pre-installed in the live builds, so you do not have to mount a guest additions ISO.
When It Will Not Boot
Almost every failure at this point comes from one of five causes, and each one has a different fix.
| Symptom | Cause and fix |
|---|---|
| VirtualBox reports that VT-x or AMD-V is not available | Hardware virtualization is switched off in the firmware, or another hypervisor holds it. Enable it in the BIOS or UEFI and close Hyper-V or WSL2 sessions |
| Extraction fails near the end | The archive is damaged. Check the SHA256 again and re-download, ideally over the torrent |
| Extraction stops with no space left | The 16 GB disk needs room beside the 3.7 GiB archive. Delete the archive only once the folder is complete |
| The VM opens to a black screen or an EFI shell | The .vdi is missing or was moved away from the .vbox. Put them back in one folder and add the machine again |
| Kali feels slow after login | The default 2048 MB of RAM is the usual cause. Shut the guest down and raise it in Settings |
If the machine refuses to find its disk in a different way, VirtualBox’s no bootable medium error covers the boot order and controller settings that cause it.
What to Do Once Kali Is Running
The image is a working penetration testing system, so the useful next step is learning what is already installed rather than installing more. Start with the command set, then move to the network basics every lab depends on.
- Kali Linux commands covers the tools the image ships and what each one does
- Finding your IP address is the first check before any scan or capture
- Installing ngrok on Kali gives you a route in from outside your own network
- Installing Pyrit shows how to add a tool that is not in the default image
- Installing from the ISO instead is the route to take when you want to control partitioning and the package selection
Whichever route you take, snapshot before an experiment and roll back after it, so the host stays untouched.
