#brickstorm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #brickstorm, aggregated by home.social.
-
BRICKSTORM case from Volexity: a clear reminder that edge appliances, MSP access and trusted network paths can become long-term blind spots for cloud compromise.
https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/
#ThreatIntelligence #CyberSecurity #APT #BRICKSTORM #Microsoft365 #CloudSecurity #DFIR
-
VerdantBamboo (UNC5221): il gruppo APT cinese che resta invisibile per 18 mesi con tre backdoor inedite
Volexity ricostruisce un'intrusione durata 18 mesi da parte del gruppo APT cinese VerdantBamboo/UNC5221. Tre backdoor inedite — BRICKSTORM, PLENET e AGENTPSD — deployate su appliance senza EDR per bypassare le Conditional Access Policy di Microsoft 365. Il gruppo è tornato pochi giorni dopo la remediation. -
Chinese #APT deploys new #malware to keep access to hacked networks
#China #cybersecurity #UNC5221 #Brickstorm #Planet #AgentPSD #VerdantBamboo
-
VerdantBamboo: Just Another BRICKSTORM in the Firewall
#VerdantBamboo #Plenet #AGENTPSD #BRICKSTORM
https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/ -
@volexity has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. This case involved the breach of the victim organization’s MSP and multiple malware implants found on firewalls, cloud storage sync devices & NAS appliances. VerdantBamboo used a #0day privilege escalation exploit in the process and was also observed using administrative access to the victim organization's firewall to enable a custom VPN.
For more details on how the incident unfolded, the malware used by the threat actor, and the end goal of the intrusion, check out the full blog post: https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/ -
Threat Intelligence vSphere and BRICKSTORM Malware: A Defender's Guide
#BRICKSTORM
https://cloud.google.com/blog/topics/threat-intelligence/vsphere-brickstorm-defender-guide/ -
#CISA Updates #BRICKSTORM Backdoor Malware Analysis Report
-
CISA, NSA, and Canadian Cyber Centre update #Brickstorm analysis with new Rust-based variants
-
Joint malware analysis report on #Brickstorm backdoor
https://www.cyber.gc.ca/en/news-events/joint-malware-analysis-report-brickstorm-backdoor
-
CISA and Partners Release Update to Malware Analysis Report #BRICKSTORM Backdoor
-
„#Brickstorm“-Hintertür in #VMwarevSphere: Warnung vor Angriff aus #China 🇨🇳 | Security https://www.heise.de/news/Brickstorm-Hintertuer-in-VMware-vSphere-Warnung-vor-Angriff-aus-China-11103648.html #VMware #vSphere
-
BRICKSTORM Backdoor
"The Cybersecurity and Infrastructure Security Agency (CISA) analyzed eight BRICKSTORM samples obtained from victim organizations. BRICKSTORM is a custom Executable and Linkable Format (ELF) Go-based backdoor. "
MISP standard and STIX files available at the following location:
🔗 https://cti-transmute.org/convert/detail/30
#backdoor #cti #brickstorm #malware #threatintel #threatintelligence #cybersecurity
-
Chinese State Hackers are using new #BRICKSTORM malware against VMware systems according to a joint alert from US and Canadian agencies.
Read: https://hackread.com/chinese-state-hackers-brickstorm-vmware-systems/
-
#PRC State-Sponsored Actors Use #BRICKSTORM Malware Across Public Sector and Information Technology Systems
-
Brickstorm – backdoor po cichu wykradający dane z systemów amerykańskich organizacji
Brickstorm to backdoor napisany w Go. Pierwsze wzmianki o nim pojawiły się w kwietniu 2024 roku. Malware pełnił funkcję serwera WWW, narzędzia do manipulacji plikami, droppera, przekaźnika SOCKS oraz narzędzia do wykonywania poleceń powłoki. Badacze przypisali te ataki klastrowi aktywności grupy UNC5221, znanej z wykorzystywania podatności typu zero-day w produktach...
-
"Google Threat Intelligence Group (GTIG) is tracking BRICKSTORM malware activity, which is being used to maintain persistent access to victim organizations in the United States. Since March 2025, Mandiant Consulting has responded to intrusions across a range of industry verticals, most notably legal services, Software as a Service (SaaS) providers, Business Process Outsourcers (BPOs), and Technology. The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims.
We attribute this activity to UNC5221 and closely related, suspected China-nexus threat clusters that employ sophisticated capabilities, including the exploitation of zero-day vulnerabilities targeting network appliances. While UNC5221 has been used synonymously with the actor publicly reported as Silk Typhoon, GTIG does not currently consider the two clusters to be the same.
These intrusions are conducted with a particular focus on maintaining long-term stealthy access by deploying backdoors on appliances that do not support traditional endpoint detection and response (EDR) tools. The actor employs methods for lateral movement and data theft that generate minimal to no security telemetry. This, coupled with modifications to the BRICKSTORM backdoor, has enabled them to remain undetected in victim environments for 393 days, on average. Mandiant strongly encourages organizations to reevaluate their threat model for appliances and conduct hunt exercises for this highly evasive actor. We are sharing an updated threat actor lifecycle for BRICKSTORM associated intrusions, along with specific and actionable steps organizations should take to hunt for and protect themselves from this activity."
https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign?e=48754805
#CyberSecurity #China #Surveillance #Brickstorm #Malware #USA #ZeroDays
-
China-Linked Hackers Hit US Tech Firms with BRICKSTORM Malware https://hackread.com/china-hackers-hit-us-tech-firms-brickstorm-malware/ #Cybersecurity #Vulnerability #CyberAttack #BRICKSTORM #Security #Mandiant #Malware #UNC5221 #Google #China #Linux #0day #SaaS
-
Google China-linked hackers (#UNC5221) are targeting US SaaS and tech firms using the new BRICKSTORM malware, exploiting zero-day flaws, Mandiant has found.
Read: https://hackread.com/china-hackers-hit-us-tech-firms-brickstorm-malware/
-
BRICKSTORM Backdoor Hits Tech and Legal Firms with Stealthy New Campaign https://gbhackers.com/brickstorm-backdoor/ #CyberSecurityNews #cybersecurity #BRICKSTORM
-
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors
#BRICKSTORM #UNC5221
https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign -
Chinese threat actor UNC5221 has significantly upgraded their BRICKSTORM malware with triple-layer encryption that renders most security monitoring ineffective, according to NVISO Security. Now targeting both Linux and Windows environments, this sophisticated threat uses traffic tunneling instead of direct command execution to avoid detection. European strategic industries are primary targets.
#SecurityLand #CyberWatch #CyberSecurity #ThreatIntelligence #APT #Brickstorm
-
Happy Tuesday everyone!
In Part 4 of the "Investigating Ivanti" series, the Mandiant (now part of Google Cloud) researchers highlight how the adversaries were able to laterally move through the environment to the vCenter server. From there they created three virtual machines mimicking their naming convention to blend in with the environment they were in. Leveraging another masquerading technique, UNC5221 then downloaded their backdoor, #Brickstorm, and named it "vami-http" which looks like a legitimate vCenter process. As always, this was a very interesting read but take a look for yourself to see the details I didn't mention. Enjoy and Happy Hunting!
Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies
https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday