logo

Chinese APT deploys new malware to keep access to hacked networks

ID: cb40605b-a95d-557c-b4df-e7d366e5b083

STIX ID: report--cb40605b-a95d-557c-b4df-e7d366e5b083

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Bill Toulas

...
...

Volexity and other vendors attribute sustained intrusions against US organizations to UNC5221 (VerdantBamboo), which used the Brickstorm backdoor (Golang and Rust variants), bespoke cross-platform backdoors Plenet and AgentPSD, and credential/SSL VPN abuse to persist for at least 18 months; the actor also compromised an MSP and leveraged zero-day/exploit techniques against edge devices, prompting published IOCs and vendor advisories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.