logo

CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks

ID: f555c106-100d-5288-805f-053786b5337c

STIX ID: report--f555c106-100d-5288-805f-053786b5337c

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Rob Wright

...
...

CISA (with NSA and the Canadian Cyber Security Centre) warned of ongoing intrusions by PRC-linked actors using the Go-based Brickstorm backdoor to compromise VMware vSphere/vCenter environments. Brickstorm enables stealthy, persistent access with layered encrypted C2 (HTTPS, WebSockets, nested TLS, DoH), interactive shell access, and self-repairing persistence; attackers have stolen AD databases and VM snapshots to extract credentials and maintained access for months. The agencies detailed intrusion activity, highlighted exploitation pathways tied to prior Ivanti zero-day activity, and recommended hardening VMware instances, restricting RDP/SMB from DMZ, monitoring service accounts, and blocking unauthorized DoH.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.