Cyber Security News

China-Nexus Hackers Target VMware vCenter Systems to Deploy Web Shells and Malware Implants

Throughout 2025, CrowdStrike has identified multiple intrusions targeting VMware vCenter environments at U.S.-based entities, in which newly identified China-nexus adversary WARP PANDA deployed BRICKSTORM malware.

WARP PANDA exhibits sophisticated technical capabilities, advanced operations security skills, and extensive knowledge of cloud and virtual machine environments.

In addition to BRICKSTORM, WARP PANDA has deployed JSP web shells and two new implants for ESXi environments Junction and GuestConduit during their operations.

WARP PANDA demonstrates exceptional stealth and focuses on maintaining persistent, long-term, covert access to compromised networks.

Their operations align with intelligence-collection requirements that support the People’s Republic of China’s strategic interests.

VMware vCenter Systems

During summer 2025, CrowdStrike identified multiple instances where WARP PANDA targeted VMware vCenter environments at U.S. legal, technology, and manufacturing entities.

The adversary maintained persistent access to compromised networks, with one intrusion providing initial access dating to late 2023.

Beyond deploying JSP web shells and BRICKSTORM on VMware vCenter servers, WARP PANDA introduced two previously unobserved Golang-based implants Junction and GuestConduit on ESXi hosts and guest VMs respectively.

WARP PANDA frequently gains initial access by exploiting internet-facing edge devices before pivoting to vCenter environments using valid credentials or vCenter vulnerabilities.

For lateral movement, the adversary employs SSH and the privileged vCenter management account vpxuser.

In some instances, CrowdStrike identified Secure File Transfer Protocol usage for data movement between hosts.

Employing tradecraft focused on stealth and OPSEC, WARP PANDA leverages techniques including log clearing, file timestomping, and creating malicious VMs unregistered in the vCenter server that are shut down after use.

To blend with legitimate network traffic, BRICKSTORM tunnels traffic through vCenter servers, ESXi hosts, and guest VMs.

CrowdStrike observed WARP PANDA staging data for exfiltration on numerous occasions. The adversary used an ESXi-compatible version of 7-Zip to extract and stage data from thin-provisioned snapshots of live ESXi guest VMs.

Separately, WARP PANDA leveraged 7-Zip to extract data from VM disks hosted on non-ESXi Linux-based hypervisors.

CrowdStrike Services also discovered evidence of vCenter server access used to clone domain controller VMs, likely collecting sensitive data such as Active Directory Domain Services databases.

They also connected to various cybersecurity blogs and a Mandarin-language GitHub repository. During at least one intrusion, the adversary specifically accessed email accounts of employees working on topics aligning with Chinese government interests.

Malware Arsenal Analysis

BRICKSTORM is a Golang-based backdoor frequently masquerading as legitimate vCenter processes such as updatemgr or vami-http.

The implant features tunneling and file management capabilities enabling filesystem browsing and file upload/download operations.

BRICKSTORM uses WebSockets to communicate with command-and-control infrastructure over TLS, employing multiple methods to obfuscate C2 communications and circumvent network monitoring.

These include DNS-over-HTTPS for C2 domain resolution, multiple nested TLS channels for C2 sessions, and leveraging public cloud services such as Cloudflare Workers and Heroku for C2 infrastructure.

Junction is a Golang-based implant for VMware ESXi servers that masquerades as a legitimate ESXi service by listening on port 8090, also used by the legitimate VMware service vvold.

Exploited Vulnerabilities

WARP PANDA has exploited multiple vulnerabilities in edge devices and VMware vCenter environments during operations.

VulnerabilityDescription
CVE-2024-21887 and CVE-2023-46805Vulnerabilities affecting Ivanti Connect Secure VPN appliances and Ivanti Policy Secure gateways; this exploit chain bypasses authentication, enabling arbitrary remote command execution
CVE-2024-38812Heap-overflow vCenter vulnerability in the DCERPC protocol’s implementation
CVE-2023-46747Authentication-bypass vulnerability affecting select F5 BIG-IP devices
CVE-2023-34048Out-of-bounds write vCenter vulnerability in the DCERPC protocol’s implementation; can lead to remote code execution
CVE-2021-22005Critical-severity vulnerability affecting vCenter servers

WARP PANDA demonstrates cloud-conscious capabilities, moving laterally, accessing sensitive data, and establishing persistence in cloud environments.

In late summer 2025, the adversary exploited access to multiple entities’ Microsoft Azure environments, primarily targeting Microsoft 365 data stored in OneDrive, SharePoint, and Exchange.

In one instance, the adversary obtained user session tokens likely by exfiltrating browser files and tunneled traffic through BRICKSTORM implants to access Microsoft 365 services via session replay. The adversary accessed and downloaded sensitive SharePoint files related to network engineering and incident response teams.

In at least one case, the adversary established persistence by registering a new multifactor authentication device via an Authenticator app code after initial login.

In another intrusion, WARP PANDA used the Microsoft Graph API to enumerate service principals, applications, users, directory roles, and emails.

Active since at least 2022, WARP PANDA represents a cloud-conscious targeted intrusion adversary exhibiting advanced technical skills and distinct malware deployment.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago