logo

VerdantBamboo: Just Another BRICKSTORM in the Firewall

ID: 94a71636-10b8-5cc0-99c6-bc07fb9ccd12

STIX ID: report--94a71636-10b8-5cc0-99c6-bc07fb9ccd12

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

...
...

### Executive summary Volexity investigated a long-term intrusion by VerdantBamboo (WARP PANDA/UNC5221) that compromised an Egnyte Storage Sync VM, an MSP pfSense firewall, and a Synology NAS, deploying BRICKSTORM (primary RAT), PLENET (.NET Native AOT backdoor), and AGENTPSD (Python reverse shell). The actor used credential theft and appliance-based proxying to access Microsoft 365 and internal resources while evading conditional access and EDR, with compromises persisting for at least 18 months and evidence of MSP compromise enabling lateral access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.