Google: Brickstorm malware used to steal U.S. orgs' data for over a year
ID: 73e2f620-7f05-53ae-b3ce-1f52c510b18d
STIX ID: report--73e2f620-7f05-53ae-b3ce-1f52c510b18d
Feed Name: Bleeping Computer
Brickstorm, a Go-based backdoor attributed to suspected Chinese-linked UNC5221, was used in long-term espionage against U.S. technology, legal, SaaS, and BPO organizations by exploiting edge-device zero-days (notably VMware vCenter/ESXi). The malware provides web server, file manipulation, SOCKS proxy, and shell execution capabilities to siphon emails and repository data with an average dwell time of 393 days while evading EDR on appliances; researchers released YARA rules and a scanner to help detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
