Skip to main content
Mallory
China🇨🇳 CN5 malware familiesExploits CVEs in the wild

WARP PANDA

Also known aswarp_panda

Warp Panda is a China-nexus / PRC-aligned cyber espionage threat actor tracked by CrowdStrike, also referred to in the provided content as Clay Typhoon and Storm-2416. CrowdStrike describes it as a newly identified, highly technically sophisticated adversary focused on stealthy, long-term covert access, with activity targeting U.S.-based entities including legal, technology, and manufacturing organizations, and with reporting also linking BRICKSTORM activity against U.S. entities more broadly. The content states its operations are likely aligned with the strategic interests of the People’s Republic of China. Warp Panda is strongly associated with intrusions into VMware vCenter and ESXi environments. Reported tradecraft includes deployment of JSP web shells and the BRICKSTORM Golang backdoor on VMware vCenter servers, as well as use of two additional Golang implants, Junction on ESXi hosts and GuestConduit on guest VMs. BRICKSTORM is described as supporting long-term persistence, tunneling, and file management, and as using TLS over WebSockets, DNS-over-HTTPS, nested TLS channels, and public cloud services to obfuscate command-and-control. The actor has also been reported targeting Azure cloud environments. According to the content, Warp Panda commonly gains initial access by exploiting internet-facing edge devices, then pivots into vCenter using valid credentials or vCenter vulnerability exploitation. It has used SSH, SFTP, and the built-in privileged VMware vpxuser account for persistence, privileged access, and lateral movement. Additional stealth and anti-forensic behavior described in the content includes log clearing, file timestomping, creation of malicious unregistered VMs, and tunneling traffic through vCenter servers, ESXi hosts, and guest VMs to blend with legitimate activity. The content also attributes data theft and intelligence collection activity to Warp Panda. Reported objectives and actions include staging data for exfiltration, extracting data from VM snapshots, cloning domain controller VMs to obtain sensitive Active Directory data, and accessing employee email accounts related to topics aligned with Chinese government interests. One report also notes rudimentary reconnaissance against an Asia Pacific government entity from a compromised network. The content links Warp Panda to BRICKSTORM malware attacks throughout 2025 and notes that it was one of at least three China-nexus actors reported to have exploited CVE-2023-34048. Some provided reporting also states CrowdStrike linked Warp Panda to the same activity cluster Google tracked as UNC5221, while other content distinguishes Warp Panda as a separate China-aligned adversary also associated with BRICKSTORM. Because the provided content is not fully consistent on that relationship, only the direct aliases explicitly given for Warp Panda are included here: Clay Typhoon and Storm-2416.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics37 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1133
External Remote Services
TA0002
Execution
2 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1059
Command and Scripting Interpreter
T1059.004
Unix Shell
TA0003
Persistence
6 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1078
Valid Accounts
T1133
External Remote Services
T1505
Server Software Component
T1505.003
Web Shell
T1543×3
Create or Modify System Process
T1556
Modify Authentication Process
TA0004
Privilege Escalation
5 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1068
Exploitation for Privilege Escalation
T1078
Valid Accounts
T1543×3
Create or Modify System Process
T1548
Abuse Elevation Control Mechanism
T1548.003
Sudo and Sudo Caching
TA0005
Stealth
2 techniques
T1070
Indicator Removal
T1070.004
File Deletion
T1078
Valid Accounts
TA0112
Defense Impairment
1 technique
T1556
Modify Authentication Process
TA0006
Credential Access
1 technique
T1556
Modify Authentication Process
TA0008
Lateral Movement
2 techniques
T1021
Remote Services
T1021.004
SSH
T1570
Lateral Tool Transfer
TA0011
Command and Control
6 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1090.001
Internal Proxy
T1105
Ingress Tool Transfer
T1219
Remote Access Tools
T1568
Dynamic Resolution
T1573
Encrypted Channel
IOCS

Observables

12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping21

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables12

Domains, IPs, and hashes tied to this actor, refreshed continuously.