logo

CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware

ID: 875f9641-a1fd-525a-93ad-a470ee28c87b

STIX ID: report--875f9641-a1fd-525a-93ad-a470ee28c87b

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-20

Date Updated: 2026-04-21

Author: Dhivya

...
...

BRICKSTORM is a sophisticated ELF backdoor attributed to PRC state-sponsored actors that targets government services and IT organizations—particularly VMware vSphere environments—providing persistent interactive access, SOCKS proxying, and multi-layer encrypted C2 (HTTPS/WebSockets/nested TLS and DoH). CISA, NSA, and the Canadian Cyber Centre released updated analysis, IOCs (STIX), and detection rules (YARA, Sigma) after incident response work showed active persistence from April 2024 through September 2025 and compromise of domain controllers and ADFS systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.