logo

From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day

ID: 3e152791-2e36-5364-8b4f-b9da35397f05

STIX ID: report--3e152791-2e36-5364-8b4f-b9da35397f05

Feed Name: Threat Intelligence

Threat Score
90/100

Date Published: 2026-02-17

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant and Google Threat Intelligence Group report that UNC6201 has actively exploited a critical zero‑day (CVE-2026-22769, CVSS 10.0) in Dell RecoverPoint for Virtual Machines since mid‑2024 to deploy SLAYSTYLE web shells, BRICKSTORM, and a novel native AOT C# backdoor called GRIMBOLT, enabling root execution, persistence via modified startup scripts, and advanced VMware pivoting techniques (Ghost NICs and iptables-based Single Packet Authorization); Dell has published remediations and the report provides detection and hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.