BRICKSTORM Malware: UNC5221 Targets Tech and Legal Sectors in the United States
ID: 78c6cd7f-f5dd-58df-9c20-e0d010d57e3c
STIX ID: report--78c6cd7f-f5dd-58df-9c20-e0d010d57e3c
Feed Name: Resources-2
BRICKSTORM is a cross-platform Go backdoor used by UNC5221 to gain persistent, stealthy access to appliance and management-plane systems; operators exploit public-facing management interfaces, deploy obfuscated implants and an in-memory vCenter servlet (BRICKSTEAL) to harvest credentials, clone VMs offline to extract ntds.dit, and pivot via a SOCKS proxy while using HTTPS/DoH and ephemeral infrastructure for C2 and exfiltration. The report maps these behaviors to MITRE ATT&CK, highlights targeted sectors (legal, SaaS, BPO, technology), documents long dwell times and sophisticated evasion techniques, and includes detection/mitigation recommendations and simulation artifacts from Picus.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
