China-Linked Warp Panda Targets North American Firms in Espionage Campaign
ID: b174f3b8-70b8-57b6-9ffa-1271e9a85d28
STIX ID: report--b174f3b8-70b8-57b6-9ffa-1271e9a85d28
Feed Name: Infosecurity Magazine (News)
CrowdStrike identified Warp Panda, a sophisticated PRC-aligned cyber-espionage actor active since at least 2022, conducting long-term persistent intrusions against North American legal, technology and manufacturing firms by compromising internet-facing edge devices and VMware vCenter environments. The actor deployed BRICKSTORM (a Golang backdoor) and two novel Golang implants (Junction and GuestConduit), leveraged valid credentials and vCenter vulnerabilities, used SSH/SFTP and log-tampering for lateral movement and data exfiltration, and tunneled traffic through vCenter/ESXi/guest VMs; CISA published a joint advisory confirming BRICKSTORM-based persistence on vSphere platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
