logo

CISA warns of Chinese "BrickStorm" malware attacks on VMware servers

ID: 81849cb6-ed30-56d5-9500-0d174c9ebca7

STIX ID: report--81849cb6-ed30-56d5-9500-0d174c9ebca7

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-12-04

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA, NSA, and Canada’s Cyber Centre warn that Chinese-linked actors deployed Brickstorm malware against VMware vSphere/ESXi servers to create hidden rogue VMs, steal cloned VM snapshots and Active Directory data, and maintain long-term persistence (observed April 2024–September 2025); the advisory (corroborated by CrowdStrike and Google reporting) details layered encryption, DoH tunneling, SOCKS proxying, and self-reinstating persistence and provides IOCs and detection guidance (YARA/Sigma, blocking unauthorized DoH, network segmentation) for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.