Ghosts in the Hypervisor: Mandiant Exposes the 400-Day vSphere Takeover
ID: 78433a7a-68b7-5096-94f1-19aeab28a389
STIX ID: report--78433a7a-68b7-5096-94f1-19aeab28a389
Feed Name: securityonline.info
**Executive summary:** Mandiant reports that advanced threat actors (tracked as BRICKSTORM) are compromising VMware vSphere control planes—vCenter Server Appliance and ESXi—to establish persistent, kernel-level footholds that evade traditional EDR; they deploy malware such as BRICKSTEAM to harvest credentials and spread across environments, maintain unusually long dwell times (average 393 days), and exploit identity and architecture weaknesses, prompting urgent recommendations for encrypted syslog (TCP/TLS), certificate validation, agentless kernel-level monitoring at the Photon OS layer, and extended remote log retention.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
