BRICKSTORM backdoor exposed: CISA warns of advanced China-backed intrusions
ID: 75744332-2076-5baa-b7e1-5b411ee7c1a7
STIX ID: report--75744332-2076-5baa-b7e1-5b411ee7c1a7
Feed Name: Security Affairs
Threat Score
CISA and industry sources warn that BRICKSTORM, a sophisticated China-linked backdoor observed since March 2024, provides stealthy long-term persistence on VMware vSphere and Windows systems; actors used stolen credentials, VM snapshot theft, rogue VMs, layered encrypted C2 (HTTPS/WebSockets/nested TLS, DoH), SOCKS proxying, and VSOCK to move laterally and exfiltrate data, compromising government services and IT sector targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
