logo

BRICKSTORM Espionage Backdoor Targeting U.S. Tech and Legal Sectors (Campaign)

ID: 07dc20f8-7c82-5a0a-bb4b-a7dbeb95ce06

STIX ID: report--07dc20f8-7c82-5a0a-bb4b-a7dbeb95ce06

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2025-09-25

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

BRICKSTORM is an active espionage campaign deploying a Go backdoor with SOCKS proxying to Linux/BSD network and edge appliances (notably VMware vCenter/ESXi) to harvest valid credentials and move laterally; operators use BRICKSTEAL (Tomcat/vCenter SSO credential hook), SLAYSTYLE (JSP web shell), VM cloning to exfiltrate sensitive VM contents without booting, and cloud-hosted C2s (Cloudflare Workers/Heroku) with DNS-over-HTTPS resolution to avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.