VerdantBamboo is a apt_group tracked across 2 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed June 5, 2026; most recent activity June 5, 2026.
The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…