BRICKSTORM Espionage Backdoor Targeting U.S. Tech and Legal Sectors (Campaign)
ID: 07dc20f8-7c82-5a0a-bb4b-a7dbeb95ce06
STIX ID: report--07dc20f8-7c82-5a0a-bb4b-a7dbeb95ce06
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-09-25
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
BRICKSTORM is an active espionage campaign deploying a Go backdoor with SOCKS proxying to Linux/BSD network and edge appliances (notably VMware vCenter/ESXi) to harvest valid credentials and move laterally; operators use BRICKSTEAL (Tomcat/vCenter SSO credential hook), SLAYSTYLE (JSP web shell), VM cloning to exfiltrate sensitive VM contents without booting, and cloud-hosted C2s (Cloudflare Workers/Heroku) with DNS-over-HTTPS resolution to avoid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
