HomeSecurityChinese hackers exploit VMware vCenter environments

Chinese hackers exploit VMware vCenter environments

A new, advanced threat actor dubbed WARP PANDAis targeting critical infrastructure across the United States, in VMware vCenter.

See also: CISA cites Chinese hackers using BRICKSTORM

VMware vCenter

The malicious actor, operating under the name WARP PANDA , has demonstrated impressive technical skills in infiltrating VMware vCenter environments in organizations across the legal, technology, and industrial sectors. The emergence of this group marks a significant escalation in cloud attacks, with a particular focus on gaining long-term access to sensitive networks and data repositories.

The attack campaign shows a deliberate and methodical mode of action, with evidence suggesting that some intrusions date back as far as late 2023.

WARP PANDA operates with advanced knowledge of cloud infrastructures and virtual machine environments, which allows it to move seamlessly across complex network topologies.

See also: Chinese hackers APT31 target Russian IT companies

Chinese hackers exploit VMware vCenter environments

Attackers begin their operations by targeting internet-facing edge devices, before moving on to vCenter, exploiting known security vulnerabilities or using compromised credentials to establish a presence on victims' networks.

CrowdStrike security researchers identified and tracked this group after discovering multiple coordinated attacks throughout 2025.

They documented how WARP PANDA used three distinct tools: the BRICKSTORM malware , JSPwebshells , and two previously unknown implants named Junction and GuestConduit .

See also: Chinese APT24 distributes BADAUDIO malware

Chinese hackers exploit VMware vCenter environments

This comprehensive toolset demonstrates the team's commitment to maintaining continuous access while evading detection mechanisms within compromised environments.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS