logo

CISA, NSA warn of China’s BRICKSTORM malware after incident response efforts

ID: 28f6e449-db91-523e-81ec-352db386a4c4

STIX ID: report--28f6e449-db91-523e-81ec-352db386a4c4

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-12-04

Date Updated: 2026-05-01

...
...

CISA, NSA and the Canadian Centre for Cyber Security, with private-sector reporting from CrowdStrike and Mandiant, warn of BRICKSTORM — a sophisticated, stealthy backdoor attributed to PRC state-sponsored actors that targets VMware vSphere and Windows to create hidden VMs, harvest credentials, compromise ADFS/domain controllers, and maintain long-term persistence for intelligence collection and data exfiltration across government and technology sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.