Security researchers at CrowdStrike have identified a surge of intrusions targeting VMware vCenter environments across multiple U.S.-based sectors in 2025.
The operations have been attributed to a newly identified China-nexus threat actor, WARP PANDA, known for its advanced operational security (OPSEC), stealth tactics, and in-depth knowledge of virtualized infrastructure.
WARP PANDA primarily deploys a custom Golang-based backdoor, BRICKSTORM, designed to masquerade as legitimate vCenter processes such as updatemgr or vami-http.
BRICKSTORM communicates with command-and-control (C2) servers via WebSockets over TLS, employing obfuscation techniques such as DNS-over-HTTPS and multi-layered encrypted channels.
The malware also uses legitimate cloud services, including Cloudflare Workers and Heroku, to hide its C2 infrastructure.
Alongside BRICKSTORM, CrowdStrike discovered two additional Golang implants: Junction and GuestConduit.
Junction runs on ESXi servers, listening on port 8090 (used by the legitimate VMware vvold service), enabling command execution, traffic proxying, and communication with guest VMs via VSOCK sockets.
GuestConduit, deployed inside guest VMs, establishes a VSOCK listener on port 5555 and facilitates tunneling between the guest and hypervisor layers.
Exploiting vCenter, F5, and Ivanti Flaws
CrowdStrike’s report indicates that WARP PANDA exploits several well-known vulnerabilities to gain access and maintain persistence.
The threat actor’s toolkit includes exploits for Ivanti Connect Secure (CVE‑2024‑21887, CVE‑2023‑46805), F5 BIG‑IP (CVE‑2023‑46747), and multiple VMware vCenter flaws (CVE‑2024‑38812, CVE‑2023‑34048, CVE‑2021‑22005).
Once inside, WARP PANDA moves laterally via SSH using the privileged vCenter account vpxuser and, in some cases, uses Secure File Transfer Protocol (SFTP) for data movement.
The group also displays advanced data exfiltration methods. CrowdStrike observed WARP PANDA using an ESXi-compatible 7‑Zip build to extract and compress snapshots of live virtual machines before exfiltration.
In one case, the hackers cloned domain controller VMs to access Active Directory data. Beyond on-premises systems, WARP PANDA has expanded its operations to Microsoft Azure environments.
They reportedly accessed Microsoft 365 services through stolen session tokens, downloading sensitive SharePoint and OneDrive files. The adversary sometimes registered new MFA devices to establish lasting access.
CrowdStrike assesses that WARP PANDA’s activity aligns with espionage objectives supporting the People’s Republic of China’s (PRC) strategic interests.
The actor remains highly persistent and cloud-aware, with operations focused on legal, technology, and manufacturing organizations in North America.
CrowdStrike warns that WARP PANDA’s focus on VMware and cloud ecosystems highlights the growing convergence of traditional infrastructure attacks with cloud-oriented espionage campaigns.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates