Officials warn about expansive, ongoing China espionage threat riding on Brickstorm malware
ID: a7801301-083b-57a8-8c14-9983b15881df
STIX ID: report--a7801301-083b-57a8-8c14-9983b15881df
Feed Name: CyberScoop
CISA, NSA and industry researchers disclosed the Brickstorm espionage campaign—attributed to China-linked groups such as Warp Panda/UNC5221—using a sophisticated Golang backdoor to gain and maintain persistent access across VMware vSphere and Windows environments since at least 2022; the actors have stolen configuration and identity data, targeted government and cloud/IT service providers to reach downstream victims, and relied on stealthy living-off-the-land techniques and poorly monitored edge devices, with indicators of compromise published by authorities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
