CISA warns of Chinese "BrickStorm" malware attacks on VMware servers
ID: 81849cb6-ed30-56d5-9500-0d174c9ebca7
STIX ID: report--81849cb6-ed30-56d5-9500-0d174c9ebca7
Feed Name: Bleeping Computer
CISA, NSA, and Canada’s Cyber Centre warn that Chinese-linked actors deployed Brickstorm malware against VMware vSphere/ESXi servers to create hidden rogue VMs, steal cloned VM snapshots and Active Directory data, and maintain long-term persistence (observed April 2024–September 2025); the advisory (corroborated by CrowdStrike and Google reporting) details layered encryption, DoH tunneling, SOCKS proxying, and self-reinstating persistence and provides IOCs and detection guidance (YARA/Sigma, blocking unauthorized DoH, network segmentation) for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
