VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
ID: 32098f39-f1a0-5b4d-aba3-f0b6783c50af
STIX ID: report--32098f39-f1a0-5b4d-aba3-f0b6783c50af
Feed Name: The Hacker News
Volexity attributes a prolonged China-nexus espionage campaign (VerdantBamboo) that compromised an organization and its MSP by exploiting appliance vulnerabilities and using stolen credentials to deploy a BSD variant of the BRICKSTORM backdoor plus PLENET/GRIMBOLT and AGENTPSD on Linux and NAS devices; the actor leveraged proxying and living-off-the-land techniques to access M365 and maintain persistence across devices, with evidence of tailored implants, operational security, and long dwell time.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
