Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors
ID: 5dfb9697-8f16-5453-b33d-2070fc8b7083
STIX ID: report--5dfb9697-8f16-5453-b33d-2070fc8b7083
Feed Name: Threat Intelligence
This report provides operational hunting and detection guidance for BRICKSTORM, a backdoor used to compromise network appliances and VMware infrastructure. It details attacker TTPs—such as unusual outbound Internet traffic from appliance management IPs, DoH usage, network logins to Windows systems, cloning of sensitive VMs, creation and removal of local vCenter accounts, and bulk M365 mailbox access via enterprise applications—and recommends log sources, YARA scanning of backups, and forensic artifacts (e.g., Windows UAL, Shellbags, vCenter VPXD logs) to investigate and confirm compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
