Ethical Hacking News
Google Warns China-Linked Malware to Haunt Networks for Years
Google has warned that a Chinese-linked malware campaign, known as BRICKSTORM, will haunt networks for at least two years. The malware, which was discovered by Mandiant, has been used by hackers to maintain access to organizations and companies in the US for an average of 393 days. With its sophisticated capabilities, BRICKSTORM poses a significant threat to organizations around the world.
Google warns of a new Chinese-linked malware, BRICKSTORM, that will haunt networks for at least two years. The malware has been used by hackers to maintain access to organizations in the U.S. for an average of 393 days. The attacks primarily target legal services, SaaS providers, BPOs, and technology companies. BRICKSTORM is deployed on systems that cannot run traditional EDR or antivirus software, such as routers, firewalls, and email security gateways. A free scanner has been released to help detect BRICKSTORM activity. The hackers' tactics are highly sophisticated, allowing them to remain undetected for long periods. Google's warning highlights the importance of staying vigilant in the face of cyber threats and prioritizing cybersecurity measures.
Google's Threat Intelligence Group has issued a warning that Chinese-linked malware, known as BRICKSTORM, is set to haunt networks for at least two years. The malware, which was discovered by Mandiant, a cybersecurity consulting arm of Google, has been used by hackers to maintain access to organizations and companies in the U.S. for an average of 393 days.
The attacks, which are primarily attributed to a group identified by Google as UNC5221, along with other closely related China-linked clusters, target a variety of industries. A particular focus is on legal services, SaaS providers, BPOs, and technology companies. The hackers use BRICKSTORM to maintain access to these targets, often for an extended period of time.
Evidence from Google's investigations suggests that the attackers are using BRICKSTORM on systems that cannot run traditional Endpoint Detection and Response (EDR) or antivirus software. Instead, they target network appliances like routers, firewalls, email security gateways, virtual machine managers, and hosts. The hackers also consistently target VMware vCenter and ESXi hosts.
To help organizations detect the malware, Mandiant has released a free scanner that looks for BRICKSTORM activity. The scanner works by searching for a combination of strings and hex patterns unique to the backdoor. According to Charles Carmakal, Mandiant Consulting Chief Technology Officer, the company anticipates that we're going to hear about this cyber threat for a long time.
"As more companies scan their systems, we anticipate we'll be hearing about this campaign for the next one to two years," Carmakal said. "We have no doubt companies will use this tool and find active or historic compromises." Carmakal also noted that over this two-year period, "new things will come out" about the attacks, as more victims disclose breaches.
The BRICKSTORM malware is particularly concerning because it allows hackers to remain undetected for long periods. The attackers use a combination of techniques to evade detection, including deploying BRICKSTORM on systems that cannot run traditional EDR or antivirus software.
This is not the first time that Google has warned about Chinese-linked hacking campaigns. In recent years, the company has identified several groups, including UNC5221, that have been linked to these types of attacks. The hackers use a range of techniques to evade detection, including deploying malware on systems that cannot run traditional EDR or antivirus software.
In addition to BRICKSTORM, Google's Threat Intelligence Group has also identified other malware families that are used in conjunction with the Chinese-linked hacking campaigns. These malware families include TA5050, which is used to steal credentials and data from targeted organizations.
The threat posed by BRICKSTORM and other Chinese-linked malware families cannot be overstated. Hackers have been able to maintain access to their victims for an average of 393 days, which suggests that these attackers are highly sophisticated and well-funded. The use of BRICKSTORM also raises concerns about the potential for zero-day vulnerabilities to be exploited.
Zero-day vulnerabilities refer to security flaws in software or hardware that are unknown to its developers. These vulnerabilities can be exploited by hackers to gain unauthorized access to systems and data. The use of BRICKSTORM suggests that the hackers may have access to these zero-day vulnerabilities, which could potentially allow them to maintain access to their victims for extended periods.
The threat posed by BRICKSTORM and other Chinese-linked malware families highlights the importance of staying vigilant in the face of cyber threats. Organizations must take proactive steps to protect themselves against these types of attacks, including implementing robust security measures and conducting regular risk assessments.
In conclusion, Google's warning about the Chinese-linked malware campaign using BRICKSTORM is a serious concern for organizations around the world. The use of this malware highlights the sophistication and capabilities of hackers, who are able to maintain access to their victims for extended periods. It also raises concerns about the potential for zero-day vulnerabilities to be exploited.
To mitigate these risks, organizations must take proactive steps to protect themselves against cyber threats. This includes implementing robust security measures, conducting regular risk assessments, and staying up-to-date with the latest threat intelligence.
By taking these steps, organizations can reduce their vulnerability to cyber threats like BRICKSTORM and other Chinese-linked malware families. It is essential that organizations prioritize their cybersecurity in light of this warning from Google's Threat Intelligence Group.
Related Information:
https://www.ethicalhackingnews.com/articles/Google-Warns-China-Linked-Malware-to-Haunt-Networks-for-Years-ehn.shtml
https://gizmodo.com/google-warns-that-china-linked-malware-will-haunt-networks-for-years-2000663320
https://www.theregister.com/2025/09/24/google_china_spy_report/
https://thehackernews.com/2025/09/unc5221-uses-brickstorm-backdoor-to.html
https://www.bleepingcomputer.com/news/security/google-brickstorm-malware-used-to-steal-us-orgs-data-for-over-a-year/
https://www.picussecurity.com/resource/blog/unc5221-cve-2025-22457-ivanti-connect-secure
Published: Wed Sep 24 15:04:41 2025 by llama3.2 3B Q4_K_M