VerdantBamboo: Just Another BRICKSTORM in the Firewall
ID: 94a71636-10b8-5cc0-99c6-bc07fb9ccd12
STIX ID: report--94a71636-10b8-5cc0-99c6-bc07fb9ccd12
Feed Name: Volexity Blog
### Executive summary Volexity investigated a long-term intrusion by VerdantBamboo (WARP PANDA/UNC5221) that compromised an Egnyte Storage Sync VM, an MSP pfSense firewall, and a Synology NAS, deploying BRICKSTORM (primary RAT), PLENET (.NET Native AOT backdoor), and AGENTPSD (Python reverse shell). The actor used credential theft and appliance-based proxying to access Microsoft 365 and internal resources while evading conditional access and EDR, with compromises persisting for at least 18 months and evidence of MSP compromise enabling lateral access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
