logo

PRC State-Sponsored Actors Use BRICKSTORM Malware Across Public Sector and Information Technology Systems

ID: f566f108-64f4-595c-8bd0-7a5068815b36

STIX ID: report--f566f108-64f4-595c-8bd0-7a5068815b36

Feed Name: All CISA Advisories

Threat Score
88/100

Date Published: 2025-12-04

Date Updated: 2026-07-30

Author: CISA

...
...

CISA reports that PRC state-sponsored actors are using the BRICKSTORM backdoor to maintain stealthy, long-term access to VMware vSphere and Windows environments—using layered encryption, DNS-over-HTTPS, and SOCKS proxies to hide C2 and facilitate lateral movement—targets include government services and IT sectors; the advisory provides analysis references, YARA/Sigma detection rules, mitigation guidance, and contact information for reporting incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.