logo

BRICKSTORM backdoor exposed: CISA warns of advanced China-backed intrusions

ID: 75744332-2076-5baa-b7e1-5b411ee7c1a7

STIX ID: report--75744332-2076-5baa-b7e1-5b411ee7c1a7

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2025-12-05

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA and industry sources warn that BRICKSTORM, a sophisticated China-linked backdoor observed since March 2024, provides stealthy long-term persistence on VMware vSphere and Windows systems; actors used stolen credentials, VM snapshot theft, rogue VMs, layered encrypted C2 (HTTPS/WebSockets/nested TLS, DoH), SOCKS proxying, and VSOCK to move laterally and exfiltrate data, compromising government services and IT sector targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.