logo

Your Backup Was the Backdoor

ID: 25da1e52-5a0a-579d-bad7-e0f28ab6bf38

STIX ID: report--25da1e52-5a0a-579d-bad7-e0f28ab6bf38

Feed Name: NoHackie

Threat Score
95/100

Date Published: 2026-02-20

Date Updated: 2026-04-19

...
...

**Executive summary:** Mandiant and Google TAG attribute active, long-running exploitation of a critical Dell RecoverPoint for VMs vulnerability (CVE-2026-22769, CVSS 10.0) to a suspected China-linked cluster (UNC6201); attackers used embedded Tomcat credentials to upload WAR web shells (SLAYSTYLE), install persistent backdoors (BRICKSTORM, later GRIMBOLT), and pivot into vCenter/ESXi via Ghost NICs and Single Packet Authorization to clone high-value VMs and maintain stealthy, long-term access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.