logo

Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors

ID: 5dfb9697-8f16-5453-b33d-2070fc8b7083

STIX ID: report--5dfb9697-8f16-5453-b33d-2070fc8b7083

Feed Name: Threat Intelligence

Threat Score
85/100

Date Published: 2025-09-24

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report provides operational hunting and detection guidance for BRICKSTORM, a backdoor used to compromise network appliances and VMware infrastructure. It details attacker TTPs—such as unusual outbound Internet traffic from appliance management IPs, DoH usage, network logins to Windows systems, cloning of sensitive VMs, creation and removal of local vCenter accounts, and bulk M365 mailbox access via enterprise applications—and recommends log sources, YARA scanning of backups, and forensic artifacts (e.g., Windows UAL, Shellbags, vCenter VPXD logs) to investigate and confirm compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.