Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary
ID: 09c2b46e-84cb-5e45-88de-d4e66c403434
STIX ID: report--09c2b46e-84cb-5e45-88de-d4e66c403434
Feed Name: Crowdstrike Blog
Threat Score
CrowdStrike identified WARP PANDA, a China-aligned APT, conducting sophisticated, long-term intrusions against U.S. VMware vCenter and ESXi environments in 2025, deploying Golang implants BRICKSTORM, Junction, and GuestConduit plus JSP web shells to tunnel traffic, communicate via VSOCK, stage and exfiltrate data, and clone domain controller VMs while leveraging valid credentials, vCenter services, and OPSEC techniques to maintain covert persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
