Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access
ID: 64da3c8c-4ea2-5aa2-815b-5db8346eb450
STIX ID: report--64da3c8c-4ea2-5aa2-815b-5db8346eb450
Feed Name: ThreatCluster
VerdantBamboo (UNC5221) has been maintaining undetected access for at least 18 months by compromising MSPs and exploiting zero-day vulnerabilities in edge devices, deploying the Brickstorm backdoor (evolved from Golang to Rust) alongside Plenet and AgentPSD to persist in Microsoft 365, VMware, storage sync systems and network appliances; investigators recommend patching affected products, monitoring SSL VPN and WebSocket traffic, hardening conditional access, and auditing MSP environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
