Warp Panda is a China-nexus cyber espionage threat actor assessed to operate in support of the People’s Republic of China’s strategic intelligence interests. The group has been linked to sustained intrusions against U.S.-based organizations, including entities in the legal, technology, and manufacturing sectors, and has also shown interest in government-related targets and cloud-hosted enterprise resources. Security reporting has associated Warp Panda with the aliases Clay Typhoon and Storm-2416. Warp Panda is notable for targeting virtualization and hybrid-cloud infrastructure, especially VMware vCenter and ESXi environments, as well as associated guest virtual machines and some Azure and Microsoft 365 resources. The actor has been observed gaining initial access through exploitation of internet-facing edge devices, then pivoting into virtualization management layers using valid credentials or exploitation of vCenter vulnerabilities. Reported tradecraft includes abuse of the built-in VMware vpxuser account for persistence, privileged access, and lateral movement. The group is strongly associated with BRICKSTORM, a Golang backdoor used for long-term covert persistence, tunneling, file management, and command execution. In VMware-focused operations, Warp Panda has also deployed JSP web shells and additional Golang implants known as Junction and GuestConduit. These tools enable command execution on ESXi hosts, traffic proxying, and communication between hypervisors and guest VMs, reflecting deep familiarity with VMware internals. Warp Panda has also been linked to hidden or unregistered malicious virtual machines, tunneling through vCenter, ESXi, and guest systems to blend with legitimate administrative traffic, and staging data from VM snapshots for exfiltration. In some cases, the actor reportedly cloned domain controller virtual machines, likely to obtain sensitive Active Directory data. Operationally, Warp Panda demonstrates strong stealth and OPSEC. Observed techniques include log clearing, timestomping, persistence mechanisms designed to survive disruption, use of legitimate administrative channels such as SSH and SFTP, and emphasis on appliances and infrastructure that often lack traditional endpoint monitoring. The actor’s campaigns are characterized by long dwell time and covert access rather than disruptive or destructive effects, consistent with espionage objectives. Warp Panda has also been cited in reporting on exploitation of VMware-related vulnerabilities, including activity involving CVE-2023-34048. Some reporting links BRICKSTORM activity to both Warp Panda and the China-linked cluster UNC5221; while overlaps in tooling and targeting have been noted, public reporting does not conclusively establish them as the same actor. Overall, Warp Panda is best characterized as a technically sophisticated PRC-aligned intrusion set specializing in persistence within virtualization, identity, and cloud-adjacent enterprise infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-aligned adversary linked to the use of BRICKSTORM in attacks targeting U.S. entities.
China-linked actor attributed by CrowdStrike to Brickstorm backdoor activity targeting VMware vCenter servers in US legal, technology, and manufacturing companies.
Abused default/vendor-configured credentials (VMware vpxuser) to persist on vCenter/ESXi and enable privileged access and lateral movement.
Cited as a China-nexus threat actor that previously exploited a VMware vCenter Server DCERPC vulnerability (CVE-2023-34048).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.