PRC State-Sponsored Actors Use BRICKSTORM Malware Across Public Sector and Information Technology Systems
ID: f566f108-64f4-595c-8bd0-7a5068815b36
STIX ID: report--f566f108-64f4-595c-8bd0-7a5068815b36
Feed Name: All CISA Advisories
Threat Score
CISA reports that PRC state-sponsored actors are using the BRICKSTORM backdoor to maintain stealthy, long-term access to VMware vSphere and Windows environments—using layered encryption, DNS-over-HTTPS, and SOCKS proxies to hide C2 and facilitate lateral movement—targets include government services and IT sectors; the advisory provides analysis references, YARA/Sigma detection rules, mitigation guidance, and contact information for reporting incidents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
