CISA and NSA Warns of BRICKSTORM Malware Attacking VMware ESXi and Windows Environments
ID: 8b0ae3d1-defd-5ad2-ae01-804e6c8b7f37
STIX ID: report--8b0ae3d1-defd-5ad2-ae01-804e6c8b7f37
Feed Name: cybersecurityNews.com
CISA, the NSA, and the Canadian Centre for Cyber Security released a joint advisory on BRICKSTORM, a Go-based backdoor used by PRC state-sponsored actors to gain long-term persistence in VMware vSphere/ESXi and Windows environments; the malware leverages DoH for resilient C2 resolution, upgrades HTTPS to WebSocket/TLS tunnels (using multiplexers like smux/Yamux), abuses VSOCK for inter-VM data exfiltration, implements self-reinstallation and SOCKS-based protocol tunneling for lateral movement, and was observed enabling theft of VM snapshots and ADFS cryptographic keys — agencies recommend patching vSphere, restricting DoH, increasing monitoring of service accounts, and performing disk-based forensic analysis to detect static persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
