logo

BRICKSTORM Malware: UNC5221 Targets Tech and Legal Sectors in the United States

ID: 78c6cd7f-f5dd-58df-9c20-e0d010d57e3c

STIX ID: report--78c6cd7f-f5dd-58df-9c20-e0d010d57e3c

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2025-09-25

Date Updated: 2026-07-22

Author: Huseyin Can YUCEEL

...
...

BRICKSTORM is a cross-platform Go backdoor used by UNC5221 to gain persistent, stealthy access to appliance and management-plane systems; operators exploit public-facing management interfaces, deploy obfuscated implants and an in-memory vCenter servlet (BRICKSTEAL) to harvest credentials, clone VMs offline to extract ntds.dit, and pivot via a SOCKS proxy while using HTTPS/DoH and ephemeral infrastructure for C2 and exfiltration. The report maps these behaviors to MITRE ATT&CK, highlights targeted sectors (legal, SaaS, BPO, technology), documents long dwell times and sophisticated evasion techniques, and includes detection/mitigation recommendations and simulation artifacts from Picus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.