logo

CISA and NSA Warns of BRICKSTORM Malware Attacking VMware ESXi and Windows Environments

ID: 8b0ae3d1-defd-5ad2-ae01-804e6c8b7f37

STIX ID: report--8b0ae3d1-defd-5ad2-ae01-804e6c8b7f37

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Guru Baran

...
...

CISA, the NSA, and the Canadian Centre for Cyber Security released a joint advisory on BRICKSTORM, a Go-based backdoor used by PRC state-sponsored actors to gain long-term persistence in VMware vSphere/ESXi and Windows environments; the malware leverages DoH for resilient C2 resolution, upgrades HTTPS to WebSocket/TLS tunnels (using multiplexers like smux/Yamux), abuses VSOCK for inter-VM data exfiltration, implements self-reinstallation and SOCKS-based protocol tunneling for lateral movement, and was observed enabling theft of VM snapshots and ADFS cryptographic keys — agencies recommend patching vSphere, restricting DoH, increasing monitoring of service accounts, and performing disk-based forensic analysis to detect static persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.