logo

Google: Brickstorm malware used to steal U.S. orgs' data for over a year

ID: 73e2f620-7f05-53ae-b3ce-1f52c510b18d

STIX ID: report--73e2f620-7f05-53ae-b3ce-1f52c510b18d

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-09-24

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Brickstorm, a Go-based backdoor attributed to suspected Chinese-linked UNC5221, was used in long-term espionage against U.S. technology, legal, SaaS, and BPO organizations by exploiting edge-device zero-days (notably VMware vCenter/ESXi). The malware provides web server, file manipulation, SOCKS proxy, and shell execution capabilities to siphon emails and repository data with an average dwell time of 393 days while evading EDR on appliances; researchers released YARA rules and a scanner to help detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.