Also known as: WARP PANDA, UNC5221, tracked as, Copy Fail 2, UNC3753, Luna Moth, UNC5221 by other vendors, proprietary appliances, UTA0178, CVE-2026-22769, GRIMBOLT, SkyCloak
VerdantBamboo emerged as a highly disciplined threat actor that orchestrates long‑term, low‑profile exfiltration campaigns by targeting network edge devices—firewalls, NAS units, and cloud sync services—that lack robust endpoint protection. The initial breach typically involves exploiting an SSH connection on an unprivileged account to gain foothold in a managed storage or sync system; from there the actor escalates privileges via sudo misconfiguration, installs backdoors such as BRICKSTORM in privileged directories (/usr/sbin), and injects cron or systemd persistence mechanisms. Once internal penetration is secured, VerdantBamboo pivots to internet‑facing infrastructure. Compromised web SSL VPN credentials allow lateral movement into corporate Microsoft 365 environments, bypassing traditional conditional access controls. The actor subsequently leverages the MSP’s pfSense firewall and other appliances, deploying a .NET backdoor (PLENET/GRIMBOLT) that offers hardened persistence, and maintains resilience through an alternate Python implant (AGENTPSD). Throughout operations they use proxy or proxy‑like techniques to mask C2 traffic, encode C2 addresses, and custom‑label implants per victim, evidencing operational discipline. In its final stages the actor establishes custom VPN tunnels or backdoor channels for exfiltration and lateral movement. The campaign is characterized by a reliance on living‑off‑the‑land tactics and exploitation of publicly disclosed CVEs (CVE‑2025‑0282/28/22457, CVE‑2026‑22769) to bypass detection, indicating the actor’s intent to achieve financial gain with minimal exposure. VerdantBamboo’s operations reflect a blend of sophistication—e.g., using .NET AOT compilation and sophisticated proxying—with opportunistic tactics such as abusing misconfigurations in unmanaged edge appliances. The result is prolonged persistence, stealthy data extraction, and occasional pivot into cloud‑based services.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
VerdantBamboo is a financially driven threat actor that specializes in exploiting low‑visibility edge appliances and managed service provider (MSP) environments across a wide spectrum of sectors, including finance, healthcare, energy, and government. Leveraging misconfigurations such as sudo privilege escalation and unprotected SSH accounts, they establish persistence through cron jobs and deploy modular backdoors – notably the .NET AOT‐compiled PLENET/GRIMBOLT implant for stealthy control and a fallback Python AGENTPSD on targeted devices. Their operations often pivot from compromised MSP footholds into corporate networks to access Microsoft 365 workloads while remaining largely invisible to conventional EDR solutions.
Goals & Targeting
The actor’s strategic objective appears to be sustainable financial exploitation of low‑visibility environments that are less likely to host comprehensive monitoring or EDR solutions. By targeting edge devices belonging to a wide array of sectors—from finance and healthcare to defense and utilities—VerdantBamboo maximizes the potential return while minimizing the risk of early detection. The use of MSP infrastructure as both an entry vector and a pivot point demonstrates a desire for extended network reach, allowing for data exfiltration from high‑value corporate sources including Microsoft 365 workloads.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
VerdantBamboo’s known operations span an extended attack lifecycle, typically lasting over a year and often involving multiple phases: initial foothold via MSP‑managed services, privilege escalation through misconfigured sudo or SSH accounts, deployment of layered backdoors (PLENET/GRIMBOLT for persistence and AGENTPSD as a fallback), and pivoting into corporate Microsoft 365 environments. The actor focuses on low‑surface‑value edge appliances—firewalls like pfSense, NAS devices such as Synology—that lack modern EDR agents, which allows the implants to remain undetected for long periods. Each victim receives uniquely named backdoors, and the actor consistently uses a single or very limited set of proxy/C2 domains per operation, reflecting disciplined operational hygiene. The exploitation of recent CVEs (CVE‑2025‑0282/28/22457, CVE‑2026‑22769) to deliver malware suggests an ability to incorporate zero‑day vulnerabilities into campaigns for elevated privilege or lateral movement.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly available intelligence reports and vendor findings that collectively provide a coherent view of VerdantBamboo’s capabilities and operational patterns. Confidence in the actor’s attribution as Chinese remains moderate, given the alignment with known TTPs but limited open‑source confirmation. The data set lacks precise timelines, comprehensive coverage of all sectors, and detailed incident-level evidence for some claims, particularly regarding use of CVE-2026-22769. Consequently, while the core narrative—edge appliance focus, privilege escalation via sudo/SSH, dual backdoor approach—is well supported, details such as campaign durations, full geographic spread, or financial outcomes should be treated with cautious interpretation.
No campaigns linked yet.
No observed data linked yet.
47
Techniques
47
Tools
0
Campaigns
50
IOCs
0
Observed Data
13
Tactics