A new, advanced threat actor dubbed WARP PANDAis targeting critical infrastructure across the United States, in VMware vCenter.
See also: CISA cites Chinese hackers using BRICKSTORM

The malicious actor, operating under the name WARP PANDA , has demonstrated impressive technical skills in infiltrating VMware vCenter environments in organizations across the legal, technology, and industrial sectors. The emergence of this group marks a significant escalation in cloud attacks, with a particular focus on gaining long-term access to sensitive networks and data repositories.
The attack campaign shows a deliberate and methodical mode of action, with evidence suggesting that some intrusions date back as far as late 2023.
WARP PANDA operates with advanced knowledge of cloud infrastructures and virtual machine environments, which allows it to move seamlessly across complex network topologies.
See also: Chinese hackers APT31 target Russian IT companies

Attackers begin their operations by targeting internet-facing edge devices, before moving on to vCenter, exploiting known security vulnerabilities or using compromised credentials to establish a presence on victims' networks.
CrowdStrike security researchers identified and tracked this group after discovering multiple coordinated attacks throughout 2025.
They documented how WARP PANDA used three distinct tools: the BRICKSTORM malware , JSPwebshells , and two previously unknown implants named Junction and GuestConduit .
See also: Chinese APT24 distributes BADAUDIO malware

This comprehensive toolset demonstrates the team's commitment to maintaining continuous access while evading detection mechanisms within compromised environments.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
