CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware
ID: 875f9641-a1fd-525a-93ad-a470ee28c87b
STIX ID: report--875f9641-a1fd-525a-93ad-a470ee28c87b
Feed Name: cybersecurityNews.com
BRICKSTORM is a sophisticated ELF backdoor attributed to PRC state-sponsored actors that targets government services and IT organizations—particularly VMware vSphere environments—providing persistent interactive access, SOCKS proxying, and multi-layer encrypted C2 (HTTPS/WebSockets/nested TLS and DoH). CISA, NSA, and the Canadian Cyber Centre released updated analysis, IOCs (STIX), and detection rules (YARA, Sigma) after incident response work showed active persistence from April 2024 through September 2025 and compromise of domain controllers and ADFS systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
