China-Linked Hackers Lay Brickstorm Backdoors on Euro Networks
ID: d781fb32-5c36-5700-a866-224ee7eb81c5
STIX ID: report--d781fb32-5c36-5700-a866-224ee7eb81c5
Feed Name: Dark Reading
Researchers at Nviso identified Windows-based variants of the Brickstorm backdoor linked to UNC5221 operating against European organizations of strategic interest to China. The Windows variants provide file manager and network tunneling capabilities (used for lateral movement with valid credentials) and are designed to evade network defenses via DNS over HTTPS, nested TLS, and cloud-based C2 infrastructure; Windows builds reportedly omit direct command execution to reduce detection, and activity has been observed since at least 2022.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
