#brickstorm
🚨🚨🚨 Google released a report on "Brickstorm" this morning — a next-level, suspected China-linked campaign targeting U.S. firms. Ultra-stealthy, 400+ day dwell times, focus on stealing IP, finding zero-days, and focused on long-term cyberespionage. cyberscoop.com/chinese-cybe...
Brickstorm malware powering ‘next-level’ Chinese cyberespionage campaign
Mandiant and Google have identified “Brickstorm,” a sophisticated, suspected China-linked hacking campaign targeting U.S. tech firms, legal organizations, and BPOs. The operation often goes undetected...
cyberscoop.com
September 24, 2025 at 2:03 PM
Cloud data management company Rubrik has found traces of the Brickstorm backdoor inside its customers' backups.

Brickstorm is the backdoor planted inside networks hacked by a Chinese cyber-espionage group.

zerolabs.rubrik.com/blog/unmaski...
October 19, 2025 at 5:57 PM
We are releasing details on BRICKSTORM malware activity, a China-based threat hitting US tech to potentially target downstream customers and hunt for data on vulnerabilities in products. This actor is stealthy, and we've provided a tool to hunt for them. cloud.google.com/blog/topics/...
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors | Google Cloud Blog
BRICKSTORM is a stealthy backdoor used by suspected China-nexus actors for long-term espionage.
cloud.google.com
September 24, 2025 at 2:31 PM
Well chuffed to make my debut for Assured Intelligence with this piece examining the Brickstorm backdoor, the cyber geopolitics behind it and what businesses need to know to protect against it.

assured.co.uk/2025/ai-auto...
AI Autopsy: Shining a Light on the Brickstorm Backdoor • Assured
Danny Palmer explores the latest ways China is trying to get its hands on Western IP.
assured.co.uk
October 10, 2025 at 9:17 AM
China-linked Brickstorm malware hits US critical systems, CISA warns
www.databreachtoday.com/brickstorm-m...
Brickstorm Malware Hits US Critical Systems, CISA Warns
U.S. and Canadian cyber authorities say Chinese state-backed actors used a backdoor dubbed BRICKSTORM to maintain long-term access into critical infrastructure,
www.databreachtoday.com
December 6, 2025 at 11:19 AM
@volexity.com has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo.
[1/4]
VerdantBamboo: Just Another BRICKSTORM in the Firewall
In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The...
www.volexity.com
June 4, 2026 at 8:33 PM
Brickstorm sounds like a late aughts Lego robotics kit.

Anyway virtualization is the soft underbelly of cloud infra,
December 6, 2025 at 4:24 PM
Chinese threat actor UNC5221 has significantly upgraded their BRICKSTORM malware with triple-layer encryption that renders most security monitoring ineffective, according to NVISO Security.

#SecurityLand #CyberWatch #CyberSecurity #ThreatIntelligence #APT #Brickstorm #Malware
BRICKSTORM Malware Evolves: Deploying Triple-Layer Encryption to Bypass Enterprise Security | Security Land
Chinese-linked UNC5221 expands BRICKSTORM attack surface from Linux to Windows using three-layer encryption and tunneling to bypass security.
www.security.land
April 16, 2025 at 6:25 PM
My weekly cyber newsletter this.weekinsecurity.com is out, featuring stories on: India scrapping mandatory phone app, Coupang breach rocks South Korea, a critical React and Next.js bug is under attack, Brickstorm malware warning & more. Plus, good news in the happy corner & a brand new cyber-cat. 🐈‍⬛
this week in security — december 7 2025 edition
India scraps mandatory phone app, Coupang breach rocks South Korea, critical React and Next.js bug under attack, Brickstorm malware warning, and more.
this.weekinsecurity.com
December 7, 2025 at 4:17 PM
Rumor: F5 is one of "several critical vendors" impacted by BRICKSTORM
October 17, 2025 at 2:55 PM
!! BRAND NEW Three Buddy Problem, on React2Shell, BRICKSTORM, .gov surveillance madness, and AI agents finding smart contracts exploits @craiu.bsky.social @jags.bsky.social

LISTEN EVERYWHERE pod.link/1414525622

(Presented by ThreatLocker)
December 6, 2025 at 6:51 PM
BRICKSTORM: la backdoor stealth che minaccia tech e legale. Così agisce il gruppo spia
il blog: insicurezzadigitale.com/brickstorm-l...

#cybersecurity #brickstorm #malware #spyware
September 25, 2025 at 8:28 AM
Brickstorm: o novo malware chinês que espia empresas durante mais de um ano sem ser detetado
tugatech.com.pt
September 24, 2025 at 6:56 PM
Here is the link to the tool allowing orgs to scan for the malware
github.com/mandiant/bri...
GitHub - mandiant/brickstorm-scanner
Contribute to mandiant/brickstorm-scanner development by creating an account on GitHub.
github.com
September 24, 2025 at 2:11 PM
Anyone heard much about Brickstorm latelyl? It's seemed to go rather quiet i've noticed. Doubtful the lack of hearing much about it means that China just stopped bothering with their efforts. No way in hell they'd be dropping that.
September 18, 2026 at 10:24 PM
US and Canadian authorities warn that Chinese hackers are using the Brickstorm malware to install backdoor access within unnamed government and IT entities (A.J. Vicens/Reuters)

Main Link | Techmeme Permalink
December 5, 2025 at 3:40 AM
CISA, NSA warn of China’s BRICKSTORM malware after incident response efforts
CISA, NSA warn of China’s BRICKSTORM malware after incident response efforts
The Cybersecurity and Infrastructure Security Agency (CISA), NSA and Canadian Centre for Cyber Security published an advisory on Thursday outlining the BRICKSTORM malware based off an analysis of eight samples taken from victim organizations.
therecord.media
December 4, 2025 at 10:00 PM
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors | Google Cloud Blog cloud.google.com/blog/topics/...
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors | Google Cloud Blog
BRICKSTORM is a stealthy backdoor used by suspected China-nexus actors for long-term espionage.
cloud.google.com
October 3, 2025 at 7:27 AM
CISA has issued guidance on BRICKSTORM, a persistent backdoor affecting VMware vSphere and Windows systems in targeted sectors.

It uses encrypted channels, VM snapshot theft, and hidden VMs for long-term access...

#BRICKSTORM #CyberSecurity #CISA #ThreatIntel #VMware #Infosec #TechNews #SecOps
December 5, 2025 at 1:57 PM
“The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims.”

Old school supply chain compromise is dead, long live operational enablement compromise.
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors | Google Cloud Blog
BRICKSTORM is a stealthy backdoor used by suspected China-nexus actors for long-term espionage.
cloud.google.com
October 15, 2025 at 10:51 PM
SANS Stormcast Friday, April 18th: Remnux Cloud Environment; Erlang/OTP SSH Vuln; Brickstorm Backdoor Analysis; GPT 4.1 Safety Controversy
https://isc.sans.edu/podcastdetail/9414
April 18, 2025 at 2:00 AM
A suspected Chinese APT, UNC6201, is exploiting a zero-day in Dell RecoverPoint for Virtual Machines

cloud.google.com/blog/topics/...
UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day | Google Cloud Blog
UNC6201 utilizes a newly discovered zero-day in Dell RecoverPoint for Virtual Machines to deliver BRICKSTORM and subsequently backdoors.
cloud.google.com
February 17, 2026 at 7:26 PM
Before you head out for the weekend, don't miss today's Metcurity for the crucial cybersecurity developments you should know, including

--US, Canada warn of Chinese-linked Brickstorm malware that gains long-term access, 1/6
www.metacurity.com/us-canada-wa...
US, Canada warn of Chinese-linked Brickstorm malware that gains long-term access
Intellexa had access to personal data of Predator spyware targets, Int'l partners release AI security guide for OT orgs, Phreeli cellco doesn't ask for identifying info, Taiwan suspends Rednote over f...
www.metacurity.com
December 5, 2025 at 2:54 PM
Any correlation between BRICKSTORM and the F5 incident? The timelines roughly line up…
October 19, 2025 at 6:04 PM
I Made JEFF THE LAND SHARK in LEGO!
YouTube video by Brickstorm Studios
youtu.be
March 23, 2025 at 3:44 AM