logo

Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary

ID: 09c2b46e-84cb-5e45-88de-d4e66c403434

STIX ID: report--09c2b46e-84cb-5e45-88de-d4e66c403434

Feed Name: Crowdstrike Blog

Threat Score
90/100

Date Published: 2025-12-04

Date Updated: 2026-04-27

Author: Counter Adversary Operations

...
...

CrowdStrike identified WARP PANDA, a China-aligned APT, conducting sophisticated, long-term intrusions against U.S. VMware vCenter and ESXi environments in 2025, deploying Golang implants BRICKSTORM, Junction, and GuestConduit plus JSP web shells to tunnel traffic, communicate via VSOCK, stage and exfiltrate data, and clone domain controller VMs while leveraging valid credentials, vCenter services, and OPSEC techniques to maintain covert persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.