logo

PRC spies Brickstormed their way into critical US networks and remained hidden for years

ID: 06e33bc1-bdd2-5f59-92cc-00069a4f0f61

STIX ID: report--06e33bc1-bdd2-5f59-92cc-00069a4f0f61

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-12-04

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Government and private security firms warn that PRC-linked actors (UNC5221 / Warp Panda) have used the multi-platform Brickstorm backdoor and additional Go-based implants to gain persistent, long‑dwell access in VMware, Linux and Windows environments—compromising vCenter, domain controllers, cloud accounts and Microsoft 365 data across multiple US government, IT, and private-sector organizations, with dozens of victims observed and ongoing active targeting of downstream services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.