GuestConduit is a Golang-based network-traffic tunneling implant used by the PRC-aligned WARP PANDA threat actor in VMware virtualization environments. It executes within guest virtual machines and exposes a VSOCK listener to receive structured requests that mirror or forward traffic. GuestConduit is assessed to operate with the ESXi-host implant Junction, enabling tunneled communications between guest VMs and hypervisor infrastructure. WARP PANDA has deployed it alongside BRICKSTORM and JSP web shells during long-term espionage-focused intrusions affecting U.S. legal, technology, and manufacturing organizations. Its use supports covert access and movement through virtualized environments while blending malicious traffic with legitimate virtualization activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
WARP PANDA frequently gained initial access by exploiting internet-facing systems, subsequently pivoting into vCenter environments using either valid credentials or by exploiting known vCenter vulnerabilities, including CVE-2024-38812, CVE-2021-22005, and CVE-2023-34048.
WARP PANDA frequently gained initial access by exploiting internet-facing systems, subsequently pivoting into vCenter environments using either valid credentials or by exploiting known vCenter vulnerabilities, including CVE-2024-38812, CVE-2021-22005, and CVE-2023-34048.
WARP PANDA frequently gained initial access by exploiting internet-facing systems, subsequently pivoting into vCenter environments using either valid credentials or by exploiting known vCenter vulnerabilities, including CVE-2024-38812, CVE-2021-22005, and CVE-2023-34048.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor's toolkit also includes JSP web shells and two Golang-based implants—Junction and GuestConduit—tailored for ESXi environments.
The threat actor's toolkit also includes JSP web shells and two Golang-based implants—Junction and GuestConduit—tailored for ESXi environments.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously unobserved Golang-based implant deployed in PRC-nexus intrusions, positioned on guest VMs for covert, persistent access.
A previously undocumented network traffic–tunneling implant deployed inside a guest VM; it establishes a VSOCK listener (port 5555) to facilitate communications between guest VMs and hypervisors.
GuestConduit is a newly identified Golang-based implant used by WARP PANDA to maintain persistent access and facilitate espionage within virtualized and cloud environments. It is deployed alongside other tools to enable stealthy operations and data exfiltration.
GuestConduit is a Go-based implant deployed on guest VMs by Chinese threat actors to maintain persistence and facilitate data exfiltration in targeted VMware environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.