China’s VerdantBamboo Experimented With Three Re-Entries and Three Malware in a Company Network
ID: 29cb31e4-c423-51e9-81eb-a937a7bbe94a
STIX ID: report--29cb31e4-c423-51e9-81eb-a937a7bbe94a
Feed Name: The Cyber Express
**VerdantBamboo APT conducted an 18-month supply-chain intrusion**: attackers compromised an Egnyte Storage Sync appliance and an MSP pfSense firewall to deploy custom backdoors (BRICKSTORM, AGENTPSD, PLENET), used stolen MSP credentials and misconfigured sudo for privilege escalation, repeatedly re-entered the network after evictions, and bypassed Microsoft Entra Conditional Access by routing M365 traffic through internal IP space; the campaign exploited devices lacking EDR and weak administrative controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
