CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

VerdantBamboo

actor · actor:verdantbamboo single-source

China-nexus APT deploying BRICKSTORM on edge devices, running MSP supply-chain intrusions, bypassing M365 conditional access, and using the AGENTPSD/PLENET tooling.

Aliases: UNC5221, WARP PANDA

Coverage
4
2 about it · 2 mentions · first 2026-05-30 → last 2026-06-11
Latest activity
2026-06-05
VerdantBamboo (UNC5221 / WARP PANDA): an 18-month China-nexus intrusion that lived entirely on EDR-blind edge…
Peak priority
high
2 high
Targets
technology
sectors: technology, public-sector, energy · regions: europe
Sources cited
12
8 hosts
2026-05-304 appearances2026-06-11

Story timeline

Every entry that names VerdantBamboo, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.

  1. 2026-06-11CrowdStrike 2026 Technology Threat Landscape Report: technology is now the most-targeted sector
    mentionresearch
  2. 2026-06-05VerdantBamboo (UNC5221 / WARP PANDA): an 18-month China-nexus intrusion that lived entirely on EDR-blind edge appliances and proxied into Microsoft 365 past Conditional Access
    active-threatsVerdantBamboo (UNC5221 / WARP PANDA): an 18-month China-nexus intrusion that lived entirely on EDR-blind edge appliances and proxied into Microsoft 365 past
  3. 2026-06-02Operation Dragon Weave: China-nexus espionage against Czech government with Azure Blob Storage dead-drop C2
    mentiondeep-dive
  4. 2026-05-30ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset
    research
ATT&CK techniques (2 across 5 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts: Cloud Accounts
  • PersistenceValid Accounts: Cloud Accounts
  • Privilege EscalationValid Accounts: Cloud Accounts
  • StealthValid Accounts: Cloud Accounts
  • Command and ControlProxy

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-05/verdantbamboo-unc5221-warp-panda-an-18-month-china-nexus-int · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-05/verdantbamboo-unc5221-warp-panda-an-18-month-china-nexus-int · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-05/verdantbamboo-unc5221-warp-panda-an-18-month-china-nexus-int · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-05/verdantbamboo-unc5221-warp-panda-an-18-month-china-nexus-int · ATT&CK page ↗

Command and Control TA0011

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-06-05/verdantbamboo-unc5221-warp-panda-an-18-month-china-nexus-int · ATT&CK page ↗

Entries about VerdantBamboo (2)

2026-06-05 · view entry permalink →

HIGH

VerdantBamboo (UNC5221 / WARP PANDA): an 18-month China-nexus intrusion that lived entirely on EDR-blind edge appliances and proxied into Microsoft 365 past Conditional Access

Volexity attributes an incident-response case at a European organisation to a China-linked actor it tracks as VerdantBamboo (assessed with high confidence as UNC5221, also WARP PANDA), with access dating back at least 18 months (Volexity, 2026-06-04). Initial access came through the victim's MSP: the actor had planted a BSD build of the BRICKSTORM Golang backdoor on the MSP's pfSense firewall. The defining tradecraft is deliberate EDR avoidance; every implant sat on appliances that cannot run an endpoint agent (firewall, Synology NAS, a retired GroupWise server) or on an Egnyte Storage Sync Linux VM. BRICKSTORM's proxy capability on the Storage Sync host let the actor route authentication to the victim's M365 tenant through that appliance's trusted egress IP, defeating Conditional Access rules that would have blocked an unrecognised source address (T1090 internal proxy, T1078.004 cloud accounts). After Volexity's first remediation, VerdantBamboo simply re-authenticated to the firewall with stolen admin credentials, re-enabled SSL VPN, and redeployed BRICKSTORM to the NAS, alongside two previously undocumented implants: AGENTPSD (a PyInstaller-packaged Python HTTPS reverse shell kept as a fallback) and PLENET/GRIMBOLT (a .NET Native AOT backdoor on a Linux NAS).

Why it matters to us: this is the precise threat model a federal SOC carries; an MSP relationship plus a fleet of edge appliances that are invisible to EDR by design. Detection has to move off the endpoint: hunt M365 sign-in logs for interactive auth originating from the egress IPs of NAS / storage-sync / firewall appliances (those should never originate user logins), alert on SSL-VPN re-enablement and admin auth to perimeter devices, and treat any appliance the vendor forbids you from instrumenting as an assumed-breach surface. Mandate MFA on all firewall management and SSL-VPN interfaces, and put the MSP's access to your perimeter under the same scrutiny as a privileged insider. [SINGLE-SOURCE], Volexity primary IR (.

threat05 Jun 05:00Zsingle-sourceOpen finding →

2026-05-30 · view entry permalink →

HIGH

ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset

ESET published its APT Activity Report covering October 2025 through March 2026 on 28 May 2026 (ESET WeLiveSecurity, 2026-05-28). EU- and NATO-relevant findings for public-sector defenders: Sandworm (Russia/GRU) intensified destructive winter operations against Ukrainian infrastructure and targeted a Polish energy company in December 2025; a NATO member state critical-infrastructure attack attributed with medium confidence; this represents continued Sandworm willingness to conduct wiper operations beyond Ukraine's borders. Sednit/APT28 deployed Covenant and BeardShell implants against Ukrainian military, drone manufacturers, and logistics companies. Lazarus Group ran Operation DreamJob targeting European drone manufacturers, ESET assesses this as technology acquisition for North Korea's weapons programme. Operation DangerousPassword compromised the axios JavaScript library (100+ million weekly npm downloads), injecting trojanised code and demonstrating ongoing North Korea supply-chain interest in developer ecosystem targeting. UNC5221 (China-nexus) deployed a new implant assessed as part of the SPAWN toolset, specifically targeting Ivanti VPN appliances (Connect Secure, Policy Secure); organisations running unpatched Ivanti VPN should audit for SPAWN toolset artefacts including SPAWNANT installer, SPAWNMOLE tunneller, SPAWNSNAIL SSH backdoor, and SPAWNSLOTH log-tampering utility. The report PDF is available at https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-apt-activity-report-q4-2025-q1-2026.pdf. Key defender actions: (a) confirm Sandworm wiper detection capability (file-destruction followed by MBR/VBR overwrite patterns, VSS deletion); (b) review Ivanti VPN logs for SPAWN footprints per CISA AA24-060A indicators; (c) audit npm dependency trees for axios versions <1.8.0 or 0.x released after the DangerousPassword campaign window.

annual-report30 May 05:00Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Research2
  • Deep dive1
  • Threats1

Source distribution

  • attack.mitre.org5 (42%)
  • cisa.gov1 (8%)
  • crowdstrike.com1 (8%)
  • infosecurity-magazine.com1 (8%)
  • seqrite.com1 (8%)
  • thehackernews.com1 (8%)
  • volexity.com1 (8%)
  • welivesecurity.com1 (8%)
All cited sources (12)