logo

vSphere and BRICKSTORM Malware: A Defender's Guide

ID: 63add8a3-0918-5912-a69b-7872684b45c3

STIX ID: report--63add8a3-0918-5912-a69b-7872684b45c3

Feed Name: Google Cloud Threat Intelligence

Date Published: 2026-04-02

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report assesses risks tied to the vCenter Server Appliance (VCSA), explaining how compromise of the VCSA can provide centralized control over ESXi hosts and VMs, enable total data access, and hinder recovery (especially when AD-integrated or when running end-of-life vSphere). It highlights management-plane dependencies, vSphere 7 EoL risks, and prescribes a four-phase defensive strategy—benchmarking and base controls, identity management, vSphere network hardening, and logging/forensic visibility—focusing on Photon OS and hypervisor hardening and behavioral detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.