Warped Panda is a China-nexus threat actor associated with intrusions involving the Brickstorm backdoor against VMware vCenter and broader VMware vSphere environments. The activity has been linked to Chinese state-sponsored operations and has focused on long-term, stealthy access in enterprise networks, including U.S.-based organizations. Operations attributed to Warped Panda have targeted government and technology environments through virtualization infrastructure, particularly vCenter management systems. The group has used Brickstorm, a Go-based backdoor designed for persistent access, covert command-and-control, and interactive shell access. Reported tradecraft includes persistence mechanisms that allow the malware to restart or reinstall itself, encrypted and layered communications, and use of DNS-over-HTTPS to obscure command-and-control traffic. Observed post-compromise behavior includes credential theft, lateral movement through compromised service accounts, access to domain controllers, extraction of Active Directory data, and abuse of virtualization management access to obtain virtual machine snapshots for credential extraction. The actor has also been observed creating rogue virtual machines and pivoting to identity infrastructure such as Active Directory Federation Services to extract cryptographic material. Overall, the group demonstrates strong capabilities in persistence, defense evasion, credential access, and post-exploitation within virtualized enterprise environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.