Chinese espionage group Deep Panda was linked to an opportunistic campaign that exploited the Log4Shell vulnerability on VMware Horizon servers to compromise organizations in finance, academia, cosmetics, and travel across multiple countries. Investigators said the attackers used PowerShell after initial access to fetch a script chain that installed Milestone, a DLL backdoor derived from leaked Gh0st RAT/Netbot Attacker code, for command-and-control and data theft.
Fortinet’s forensic analysis also identified a previously unknown Windows kernel rootkit named Fire Chili, deployed to hide malicious files, processes, registry keys, and network connections and signed with stolen code-signing certificates from game developers. The intrusion chain included DLL side-loading through a legitimate Synaptics-signed executable and installation of the crtsys.sys driver as a service, while attribution was supported by overlaps with Deep Panda’s historical Infoadmin RAT activity and infrastructure tied to Winnti, including the domain gnisoft[.]com.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Starting January 1, 2022, the cybersecurity community reported active attempts to exploit VMware Horizon through the Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046. The activity abused Horizon's embedded Apache Tomcat service for initial access.
Fortinet reported collecting four Fire Chili kernel driver samples that were compiled in early August 2017 and again about ten days later, indicating the malware family's development period.
CrowdStrike identified and named the Chinese intrusion group Deep Panda, describing it as one of the most advanced Chinese nation-state cyber intrusion groups.
Fortinet's FortiGuard Labs released research detailing the VMware Horizon intrusion chain, the Milestone backdoor, and the novel Fire Chili rootkit, and attributed the activity to Deep Panda while noting overlaps with Winnti-linked tradecraft and infrastructure.
Over the month preceding Fortinet's report, Deep Panda was observed opportunistically exploiting Log4Shell in vulnerable VMware Horizon servers across multiple countries and sectors including finance, academia, cosmetics, and travel. The campaign deployed the Milestone backdoor and the Fire Chili rootkit to steal sensitive information.
VMware published KB 87073 with temporary mitigations for CVE-2021-44228 and CVE-2021-45046 affecting Horizon components, including manual steps and Windows/Linux scripts to remove the JndiLookup class and disable risky Log4j behavior. The guidance emphasized that installing a fixed build was strongly recommended over relying on temporary mitigations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 104 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
cynet.com
Open sourcekb.vmware.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourcethehackernews.com
Open sourcefortinet.com
Open sourceattack.mitre.org
Open sourcesecureworks.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.