An unidentified Chinese-speaking threat actor associated with a highly sophisticated intrusion targeting VMware ESXi environments. The actor used a compromised SonicWall VPN appliance for initial access and deployed a custom exploit toolkit built around a VM escape orchestrator known as MAESTRO, along with a stealthy VSOCK-based backdoor referred to as VSOCKpuppet. Available evidence indicates the exploit chain was developed and likely operational by at least February 2024, more than a year before public disclosure of the exploited VMware vulnerabilities CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 in March 2025. The operation demonstrated advanced tradecraft across multiple stages of intrusion. Observed behaviors included exploitation of ESXi zero-days, reconnaissance, use of Domain Admin credentials, lateral movement, firewall-rule manipulation to restrict external visibility while preserving internal movement, persistence on the hypervisor, and staging of data for exfiltration. The exploit chain reportedly supported a large range of ESXi builds and used a multi-step process to leak memory, bypass protections, achieve code execution in the VMX process, escape the VM sandbox, and reach the ESXi kernel. The backdoor’s use of VSOCK for command and control reduced visibility to conventional network monitoring, and the tooling restored modified drivers to reduce detection. The actor appears well resourced and technically mature, with access to zero-day capabilities and bespoke tooling for virtualization-focused post-exploitation. Chinese-language development artifacts support assessment of a Chinese-speaking origin, but no specific named cluster, state nexus, or organizational attribution is established at high confidence. No confirmed ransomware deployment was observed in the documented intrusion, although the actor staged data for possible exfiltration and conducted extensive post-compromise activity within the victim environment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
GreyNoise attribue également à cet acteur une campagne Gitea exploitant CVE-2026-60004, ayant permis l’exfiltration de code source et d’identifiants, la persistance et le mouvement latéral.
GreyNoise associe l’acteur sinophone à des opérations WordPress antérieures en 2026, exploitant CVE-2026-63030 et CVE-2026-60137 dans une chaîne appelée « WP2Shell ».
GreyNoise associe l’acteur sinophone à des opérations WordPress antérieures en 2026, exploitant CVE-2026-63030 et CVE-2026-60137 dans une chaîne appelée « WP2Shell ».
CVE-2026-7273 est un stack-based buffer overflow affectant les firmwares 2.90(XXXX.1)C0 et antérieurs des switches Zyxel GS1900. Exploitable depuis le LAN, sans authentification, via une requête HTTP spécialement forgée, il permet l’exécution de commandes OS sur l’équipement.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.