Warp Panda North American legal, technology and manufacturing espionage campaign
Campaign
Summary
Hide ▲
Show ▼
Warp Panda is running a sophisticated cyber-espionage campaign against North American legal, technology and manufacturing firms, maintaining persistent covert access that supports intelligence collection tied to PRC interests. The operation has been active since at least 2022 and was observed again in summer 2025 targeting VMware vCenter environments. The group’s tooling and access patterns indicate a long-term espionage program rather than isolated intrusion activity.
Related Happenings
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware Activity
First: 18.02.2026 12:32
Last: 18.02.2026 12:32
Sources 1
About this happening:
**BRICKSTORM** is a **Golang backdoor** used by **PRC state-sponsored actors** to keep **long-term persistence** on **VMware vSphere**, **Windows**, and appliance environments. **...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware ActivityAbout this happening: **BRICKSTORM** is a **Golang backdoor** used by **PRC state-sponsored actors** to keep **long-term persistence** on **VMware vSphere**, **Windows**, and appliance environments. **...
Pro-Russia hacktivist OT intrusion campaign against US critical infrastructure
Campaign
First: 10.12.2025 18:00
Last: 10.12.2025 18:00
Sources 1
About this happening:
A coordinated **pro-Russia hacktivist** campaign is exploiting exposed **virtual network computing** connections and weak passwords to breach **operational technology (OT)** syste...
Pro-Russia hacktivist OT intrusion campaign against US critical infrastructure
CampaignAbout this happening: A coordinated **pro-Russia hacktivist** campaign is exploiting exposed **virtual network computing** connections and weak passwords to breach **operational technology (OT)** syste...
Warp Panda Brickstorm VMware vCenter targeting campaign
Campaign
First: 04.12.2025 20:19
Last: 04.12.2025 20:19
Sources 1
About this happening:
A **Warp Panda** targeting campaign using **Brickstorm** reached **VMware vCenter** servers on the networks of **U.S. legal, technology, and manufacturing companies** throughout *...
Warp Panda Brickstorm VMware vCenter targeting campaign
CampaignAbout this happening: A **Warp Panda** targeting campaign using **Brickstorm** reached **VMware vCenter** servers on the networks of **U.S. legal, technology, and manufacturing companies** throughout *...
BRICKSTORM backdoor persistent-access activity against VMware vCenter and Windows environments
Malware Activity
First: 04.12.2025 14:00
Last: 04.12.2025 14:00
Sources 1
About this happening:
**BRICKSTORM** is being used by **PRC state-sponsored actors** for **persistent access** in **Government** and **Information Technology** organizations, increasing the risk of ste...
BRICKSTORM backdoor persistent-access activity against VMware vCenter and Windows environments
Malware ActivityAbout this happening: **BRICKSTORM** is being used by **PRC state-sponsored actors** for **persistent access** in **Government** and **Information Technology** organizations, increasing the risk of ste...
TWOSTROKE and DEEPROOT backdoor deployment in Middle East attacks
Malware Activity
First: 18.11.2025 14:54
Last: 18.11.2025 14:54
Sources 1
About this happening:
The deployment of **TWOSTROKE** and **DEEPROOT** gave attackers persistent backdoor access for **reconnaissance**, **command execution**, and **data theft** against targeted organ...
TWOSTROKE and DEEPROOT backdoor deployment in Middle East attacks
Malware ActivityAbout this happening: The deployment of **TWOSTROKE** and **DEEPROOT** gave attackers persistent backdoor access for **reconnaissance**, **command execution**, and **data theft** against targeted organ...
Timeline
-
05.12.2025 02:00 2 articles · 5mo ago
CrowdStrike discloses Warp Panda espionage campaign
Initial DisclosureCrowdStrike identifies Warp Panda as a sophisticated cyber-espionage campaign targeting North American legal, technology and manufacturing firms, says the group has been active since at least 2022, and links summer 2025 activity to multiple VMware vCenter intrusions, BRICKSTORM, Junction and GuestConduit.
Show sources
- China-Linked Warp Panda Targets North American Firms in Espionage Campaign — www.infosecurity-magazine.com — 05.12.2025 16:30
- China-Linked Warp Panda Targets North American Firms in Espionage Campaign — www.infosecurity-magazine.com — 05.12.2025 16:30
-
04.12.2025 02:00 1 articles · 5mo ago
BRICKSTORM persistence window extends through September 3, 2025
Campaign Scope UpdateCISA analysis shows BRICKSTORM provided persistent access on victim systems from at least April 2024 through at least September 3, 2025, marking the end of a long-running persistence window tied to the campaign.
Show sources
- China-Linked Warp Panda Targets North American Firms in Espionage Campaign — www.infosecurity-magazine.com — 05.12.2025 16:30
-
04.12.2025 02:00 1 articles · 5mo ago
CISA advisory confirms BRICKSTORM long-term persistence
Detection Ioc UpdateCISA publishes a joint advisory confirming a PRC state-sponsored cyber actor is using BRICKSTORM for long-term persistence on victim systems and noting that VMware vSphere platforms have been targeted.
Show sources
- China-Linked Warp Panda Targets North American Firms in Espionage Campaign — www.infosecurity-magazine.com — 05.12.2025 16:30