Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access
ID: ab213e8e-469b-5912-9ee5-5fe91b9ceb18
STIX ID: report--ab213e8e-469b-5912-9ee5-5fe91b9ceb18
Feed Name: ThreatCluster
Threat Score
UNC5221 (VerdantBamboo) has been using the Brickstorm backdoor and newer variants (Plenet, AgentPSD) to compromise MSPs and maintain persistent access to Microsoft 365 and network infrastructure for at least 18 months, exploiting zero-day edge-device vulnerabilities and employing advanced evasion techniques; defenders are advised to patch affected products, monitor WebSocket C2 and SSL VPN anomalies, harden conditional access, and audit MSP environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
