PRC-Nexus is a cluster designation for threat activity associated with the People’s Republic of China that targets the virtualization layer in enterprise environments. Reported operations focus on VMware vCenter Server Appliance and ESXi hypervisors, where the actor seeks long-term persistence below the guest operating system and outside the visibility of many traditional endpoint detection and response controls. By operating at the management and hypervisor layers, the actor can evade security tooling centered on individual virtual machines and gain durable access to critical infrastructure. A key risk associated with this activity is compromise of the vCenter control plane, which can provide administrative control over managed ESXi hosts and virtual machines. This position enables broad post-compromise access across virtualized estates and creates a pathway to exfiltrate highly sensitive Tier-0 assets. Observed tradecraft indicates emphasis on persistence, defense evasion, lateral access opportunities enabled by privileged management systems, and data theft potential from centrally managed virtual infrastructure. The designation is associated with activity involving the BRICKSTORM backdoor in VMware vSphere environments. High-confidence reporting supports characterization of this actor as focused on virtualization-centric intrusion operations rather than commodity cybercrime or ransomware. The available information directly supports espionage-oriented objectives and long-term access in strategically valuable enterprise environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.