logo

Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access

ID: ab213e8e-469b-5912-9ee5-5fe91b9ceb18

STIX ID: report--ab213e8e-469b-5912-9ee5-5fe91b9ceb18

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-05

Date Updated: 2026-06-06

...
...

UNC5221 (VerdantBamboo) has been using the Brickstorm backdoor and newer variants (Plenet, AgentPSD) to compromise MSPs and maintain persistent access to Microsoft 365 and network infrastructure for at least 18 months, exploiting zero-day edge-device vulnerabilities and employing advanced evasion techniques; defenders are advised to patch affected products, monitor WebSocket C2 and SSL VPN anomalies, harden conditional access, and audit MSP environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.