logo

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

ID: 32098f39-f1a0-5b4d-aba3-f0b6783c50af

STIX ID: report--32098f39-f1a0-5b4d-aba3-f0b6783c50af

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: [email protected] (The Hacker News)

...
...

Volexity attributes a prolonged China-nexus espionage campaign (VerdantBamboo) that compromised an organization and its MSP by exploiting appliance vulnerabilities and using stolen credentials to deploy a BSD variant of the BRICKSTORM backdoor plus PLENET/GRIMBOLT and AGENTPSD on Linux and NAS devices; the actor leveraged proxying and living-off-the-land techniques to access M365 and maintain persistence across devices, with evidence of tailored implants, operational security, and long dwell time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.