Skip to main content
Mallory
MalwareUsed by 1 actor

Junction

Junction is a previously undocumented Golang-based implant used in VMware ESXi environments. CrowdStrike reported it being deployed on ESXi hosts alongside the BRICKSTORM malware family and the related GuestConduit implant, which runs in guest VMs. The malware has been attributed in reporting to the China-nexus threat actor WARP PANDA, and its use has been observed in intrusions targeting VMware vCenter environments at U.S.-based legal, technology, and manufacturing organizations. Reported intrusion chains commonly involved exploitation of internet-facing edge devices, pivoting into vCenter with valid credentials or vCenter vulnerability exploitation, and lateral movement using SSH and the privileged vCenter account vpxuser. High-confidence functionality described for Junction includes acting as an HTTP server, executing commands, proxying traffic, and interacting with guest VMs via VSOCK. It has been reported to masquerade as a legitimate ESXi service by listening on port 8090, a port associated in the reporting with VMware vvold. Junction appears designed to support covert communication within virtualized environments and to facilitate tunneling between ESXi hosts and guest VMs in conjunction with GuestConduit, which establishes a VSOCK listener on port 5555. Its deployment has been reported as part of stealth-focused, long-term persistence operations in VMware ecosystems.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
WARP PANDA

CrowdStrike observed the same threat group deploying previously unknown Junction and GuestConduit malware implants in VMware ESXi environments.

via bleeping computerbleepingcomputer.com
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Persistence

2 techniques
T1505.003Web ShellEvidence1

“deploying JSP web shells and BRICKSTORM on VMware vCenter servers”

T1543Create or Modify System ProcessEvidence1

“PRC state-sponsored cyber actors are using BRICKSTORM malware for long-term persistence… uploaded BRICKSTORM… to an internal VMware vCenter server… used BRICKSTORM for persistent access from at least April 2024 through… Sept. 3, 2025.”

T1543Create or Modify System ProcessEvidence1

“PRC state-sponsored cyber actors are using BRICKSTORM malware for long-term persistence… uploaded BRICKSTORM… to an internal VMware vCenter server… used BRICKSTORM for persistent access from at least April 2024 through… Sept. 3, 2025.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.