WARP PANDAWARP PANDA

Also known as: WARP PANDA

Known aliases
1

Profile

WARP PANDA is a China-nexus APT that targets VMware vCenter environments and Microsoft Azure infrastructures, primarily focusing on legal, technology, and manufacturing sectors in the U.S. The group exploits internet-facing edge devices for initial access, later pivoting to vCenter environments using compromised credentials or vulnerabilities. Their toolkit includes the BRICKSTORM backdoor, along with implants like Junction and GuestConduit, which facilitate command execution and network traffic tunneling. WARP PANDA demonstrates advanced OPSEC and aims for long-term persistence and data exfiltration aligned with the interests of the People's Republic of China.

Aliases· 1

WARP PANDA

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
SAMURAI PANDA
Actor
HURRICANE PANDA
Actor
LIMINAL PANDA
Actor
SharpPanda
Actor
BIG PANDA
Actor
WET PANDA
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.