logo

CISA Releases BRICKSTORM Malware Analysis with New YARA Rules for VMware vSphere

ID: e08b4e54-1aa7-5ccd-bf76-1c49db9715ce

STIX ID: report--e08b4e54-1aa7-5ccd-bf76-1c49db9715ce

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-21

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

CISA's analysis describes BRICKSTORM, a nation-state linked backdoor that targets VMware vSphere (vCenter and ESXi) to maintain long-term, stealthy access: attackers used stolen service account credentials and RDP to move laterally from compromised web servers to domain controllers and vCenter, exfiltrated keys from ADFS, and employed self-healing persistence and encrypted DNS-over-HTTPS/WebSocket C2; CISA released YARA and Sigma detections and mitigation guidance for affected organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.