CISA, NSA warn of China’s BRICKSTORM malware after incident response efforts
ID: 28f6e449-db91-523e-81ec-352db386a4c4
STIX ID: report--28f6e449-db91-523e-81ec-352db386a4c4
Feed Name: The Record from Recorded Future News
Threat Score
CISA, NSA and the Canadian Centre for Cyber Security, with private-sector reporting from CrowdStrike and Mandiant, warn of BRICKSTORM — a sophisticated, stealthy backdoor attributed to PRC state-sponsored actors that targets VMware vSphere and Windows to create hidden VMs, harvest credentials, compromise ADFS/domain controllers, and maintain long-term persistence for intelligence collection and data exfiltration across government and technology sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
