Beyond Endpoints: How BRICKSTORM Exposed Security Blind Spots by Lucie Cardiet
ID: b029d280-031c-5624-aeef-caf419a6708d
STIX ID: report--b029d280-031c-5624-aeef-caf419a6708d
Feed Name: Vectra AI Blog
UNC5221’s BRICKSTORM is a highly sophisticated espionage campaign that implants custom backdoors on edge appliances (VPN gateways, firewalls, VMware vCenter) to remain undetected for ~400 days, pivot to identity systems (cloning domain controllers, siphoning vCenter admin credentials, registering rogue M365 apps), and expand impact via compromised service providers; the report urges a shift from IOC/signature detection to behavior-based, cross-domain monitoring to close these visibility gaps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
