logo

Officials warn about expansive, ongoing China espionage threat riding on Brickstorm malware

ID: a7801301-083b-57a8-8c14-9983b15881df

STIX ID: report--a7801301-083b-57a8-8c14-9983b15881df

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

CISA, NSA and industry researchers disclosed the Brickstorm espionage campaign—attributed to China-linked groups such as Warp Panda/UNC5221—using a sophisticated Golang backdoor to gain and maintain persistent access across VMware vSphere and Windows environments since at least 2022; the actors have stolen configuration and identity data, targeted government and cloud/IT service providers to reach downstream victims, and relied on stealthy living-off-the-land techniques and poorly monitored edge devices, with indicators of compromise published by authorities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.