VerdantBamboo Malware Campaign Targets Edge Devices via Supply Chain Breach
ID: c2928413-1162-5a9b-acd3-0caf25837737
STIX ID: report--c2928413-1162-5a9b-acd3-0caf25837737
Feed Name: securityonline.info
VerdantBamboo is a sophisticated, long-running Chinese APT campaign that targeted unmonitored edge appliances (Egnyte Storage Sync, pfSense firewalls) and a managed service provider to gain persistent footholds, escalate privileges via insecure sudo configurations, deploy backdoors (PLENET and AGENTPSD), proxy traffic to attacker infrastructure, and pivot into cloud/M365 environments; the report warns of supply-chain risk, stealthy living-off-the-land techniques, and recommends MFA on admin interfaces and outbound traffic inspection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
