Also known as: Storm-0978, Tropical Scorpius, tracked as, UTA0178, Red Dev 61, WARP PANDA by CrowdStrike, UNC5221, SSH port forwarding, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, SHADOW-VOID-042, RomCom, the Bulldog backdoor, defense-industry organizations, Smoke Sandstorm, TA455, Yellow Liderc, Tortoiseshell, aviation, defense industries, LuoYu, foreign entities, Qilin, file transfer tools, Blue Echidna, UNC2596, GOFFEE, Fluffy Wolf, Imperial Kitten, CASCADE PANDA
WARP PANDA is a China-nexus APT that targets VMware vCenter environments and Microsoft Azure infrastructures, primarily focusing on legal, technology, and manufacturing sectors in the U.S. The group exploits internet-facing edge devices for initial access, later pivoting to vCenter environments using compromised credentials or vulnerabilities. Their toolkit includes the BRICKSTORM backdoor, along with implants like Junction and GuestConduit, which facilitate command execution and network traffic tunneling. WARP PANDA demonstrates advanced OPSEC and aims for long-term persistence and data exfiltration aligned with the interests of the People's Republic of China.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
WARP PANDA is a sophisticated China-linked advanced persistent threat (APT) group targeting critical U.S. sectors such as legal, technology, and manufacturing. The group specializes in exploiting internet-facing edge devices and VMware vCenter environments to gain initial access, then pivots to Microsoft Azure infrastructures for long-term persistence and data exfiltration. WARP PANDA's operations demonstrate advanced OPSEC practices and are aligned with Chinese national interests.
Goals & Targeting
WARP PANDA's targeting strategy suggests alignment with the strategic goals of the People's Republic of China, likely focusing on economic espionage and industrial sector dominance. The group targets sectors that hold sensitive intellectual property and competitive intelligence, such as technology and manufacturing, while also focusing on legal industries potentially for influence operations or to disrupt supply chains. Their U.S.-centric targeting indicates a focus on disrupting critical infrastructure or gathering intelligence from key global players in these sectors.
Enhanced Description
WARP PANDA is a state-sponsored APT group that has been increasingly active in compromising U.S. critical infrastructure sectors, particularly in the technology, legal, and manufacturing industries. The group's primary focus appears to be on gaining unauthorized access to VMware vCenter environments and Microsoft Azure infrastructures, leveraging sophisticated tools such as BRICKSTORM backdoor and implants like Junction and GuestConduit for command execution and network traffic tunneling. WARP PANDA utilizes a combination of initial access via internet-facing edge devices, exploitation of known vulnerabilities, and credential dumping to establish persistence within targeted networks. Their operational strategy emphasizes long-term presence to facilitate data exfiltration, likely in support of Chinese economic or strategic interests. The group's high level of operational security (OPSEC) and advanced technical capabilities make it a significant threat to organizations managing critical IT infrastructures.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
WARP PANDA's campaigns are characterized by prolonged, stealthy operations designed to maintain persistence and exfiltrate sensitive data over time. The group has demonstrated a preference for targeting high-value sectors with significant intellectual property and strategic importance to the U.S. economy. Notable patterns include initial access through vulnerable edge devices, lateral movement within networks using compromised credentials or exploit kits, and systematic data collection and exfiltration activities. While specific campaign details are not fully publicly disclosed, WARP PANDA's operations suggest a highly coordinated and state-backed approach to cyber espionage and infrastructure targeting.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in WARP PANDA's APT designation and targeting patterns based on available technical details and observed behavior. Limited data exists on the group's exact origins or campaigns prior to 2023, which introduces some uncertainty regarding its full capabilities and long-term objectives. Additional clarity would benefit from further reporting on their tactics, techniques, and procedures (TTPs).
No campaigns linked yet.
No observed data linked yet.
10
Techniques
44
Tools
0
Campaigns
30
IOCs
0
Observed Data
4
Tactics