logo

Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access

ID: 64da3c8c-4ea2-5aa2-815b-5db8346eb450

STIX ID: report--64da3c8c-4ea2-5aa2-815b-5db8346eb450

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-06-05

Date Updated: 2026-06-08

...
...

VerdantBamboo (UNC5221) has been maintaining undetected access for at least 18 months by compromising MSPs and exploiting zero-day vulnerabilities in edge devices, deploying the Brickstorm backdoor (evolved from Golang to Rust) alongside Plenet and AgentPSD to persist in Microsoft 365, VMware, storage sync systems and network appliances; investigators recommend patching affected products, monitoring SSL VPN and WebSocket traffic, hardening conditional access, and auditing MSP environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.