GroupWise is a technology platform tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
GroupWise is a technology platform tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed June 5, 2026; most recent activity June 5, 2026.
The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
GroupWise is a technology platform tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
The most recent intelligence report mentioning GroupWise on ThreatCluster is dated June 5, 2026.
Across ThreatCluster reporting, GroupWise most frequently co-occurs with Unc5221, VerdantBamboo, Warp Panda, Malware, Dell, among 12 tracked related entities.
The most significant recent cluster is “Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access” (5 articles · Updated June 5, 2026). GroupWise appears across 2 threat clusters in total, listed above with sources.
GroupWise appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.