logo

China-Linked Hackers Lay Brickstorm Backdoors on Euro Networks

ID: d781fb32-5c36-5700-a866-224ee7eb81c5

STIX ID: report--d781fb32-5c36-5700-a866-224ee7eb81c5

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-04-16

Date Updated: 2026-05-05

Author: Rob Wright

...
...

Researchers at Nviso identified Windows-based variants of the Brickstorm backdoor linked to UNC5221 operating against European organizations of strategic interest to China. The Windows variants provide file manager and network tunneling capabilities (used for lateral movement with valid credentials) and are designed to evade network defenses via DNS over HTTPS, nested TLS, and cloud-based C2 infrastructure; Windows builds reportedly omit direct command execution to reduce detection, and activity has been observed since at least 2022.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.