Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Brickstorm Malware Scandal: A Long-Term Spy Operation Targeting U.S. Organizations



The Brickstorm malware has been used to steal sensitive data from U.S.-based organizations for over a year, revealing a sophisticated espionage operation that highlights the ongoing threats posed by state-sponsored attackers.

  • Google has identified a sophisticated malware operation, Brickstorm, that secretly siphoned data from U.S.-based organizations for 393 days on average before detection.
  • The malware is attributed to Chinese hackers and utilized as a versatile backdoor with multiple functions, including web server, file manipulation tool, dropper, SOCKS relay, and shell command execution.
  • Attackers employed anti-forensics scripts to evade detection and maintain stealth, complicating forensic investigations into the breach.
  • The malware was developed as part of China-related intrusions that originated from various edge devices, laying the groundwork for the prolonged data exfiltration phase.
  • Compromised organizations were found in both technology and legal sectors, suggesting a strategic effort to infiltrate entities with significant influence.
  • The attackers collected substantial amounts of sensitive information without being detected until much later, using Brickstorm's ability to silently siphon data from its victims' networks.
  • Google attributes the attacks to the UNC5221 activity cluster and suggests that exploitation of zero-days in edge devices played a role in the initial access vector.
  • The malware was deployed on appliances not supported by Endpoint Detection and Response (EDR) solutions, including VMware vCenter/ESXi endpoints.
  • Once inside, attackers attempted to escalate privileges using a malicious Java Servlet Filter known as Bricksteal on vCenter, and cloned Windows Server VMs to extract secrets.
  • The stolen credentials were used for lateral movement and persistence, including enabling SSH on ESXi and modifying startup scripts.



  • Google has recently revealed that a sophisticated malware operation, dubbed "Brickstorm," has been secretly siphoning data from numerous U.S.-based organizations in the technology and legal sectors for an astonishing 393 days on average, before being detected.

    According to the Google Threat Intelligence Group (GTIG), this long-term persistence espionage operation is attributed to Chinese hackers, who utilized Brickstorm as a versatile backdoor that served multiple purposes. The malware's primary functions included serving as a web server, file manipulation tool, dropper, SOCKS relay, and shell command execution tool.

    The attackers' tactics were deliberately designed to evade detection and maintain a high level of stealth. They employed the use of anti-forensics scripts, which further complicated forensic investigations into the breach.

    To understand the extent of this operation, it is essential to grasp the background of Brickstorm's development. The malware was documented by Google in April 2024 as part of China-related intrusions that originated from various edge devices. These initial infections likely laid the groundwork for the prolonged data exfiltration phase.

    The attackers' objectives went beyond simple espionage; they also sought to create zero-day exploits, which could be exploited to attack other downstream victims. The fact that compromised organizations were found in both the legal and technology sectors suggests a strategic effort to infiltrate entities with significant influence.

    Furthermore, Brickstorm was used to silently siphon data from its victims' networks. In an average dwell time of 393 days, the attackers were able to collect substantial amounts of sensitive information without being detected until much later.

    The researchers attribute these attacks to the UNC5221 activity cluster, notorious for exploiting Ivanti zero-days to attack government agencies with custom malware like Spawnant and Zipline. The involvement of anti-forensics scripts further complicates the determination of the initial access vector, but it is believed that exploitation of zero-days in edge devices played a role.

    The nature of Brickstorm's deployment was equally sophisticated. It was deployed on appliances that did not support Endpoint Detection and Response (EDR) solutions, including VMware vCenter/ESXi endpoints, where it established communication with the command and control server while masquerading legitimate traffic from Cloudflare, Heroku, and other platforms.

    Once a foothold was secured, the attackers attempted to escalate privileges using a malicious Java Servlet Filter known as Bricksteal on vCenter. They also cloned Windows Server VMs to extract secrets.

    The stolen credentials were then utilized for lateral movement and persistence, which included enabling SSH on ESXi and modifying startup scripts init.d and systemd. The primary operational objective of Brickstorm was to exfiltrate emails via Microsoft Entra ID Enterprise Apps, utilizing its SOCKS proxy to tunnel into internal systems and code repositories while maintaining stealth.

    Google's observations indicate that UNC5221 has a strong focus on developers, administrators, and individuals connected to China's economic and security interests. When the operation is completed, the malware is removed from the system to hinder forensic investigations.

    Mandiant has released a free scanner script that replicates a Brickstorm YARA rule for Linux and BSD appliances. However, this tool warns that its detection capabilities might be limited due to the variety of variants present in Brickstorm, as well as not covering all persistence mechanisms or warning about vulnerable devices.

    This recent revelation highlights the ongoing threat landscape where sophisticated state-sponsored actors are continually pushing boundaries to exploit vulnerabilities. The involvement of malware like Brickstorm underscores the importance of staying vigilant and implementing robust security measures to protect against such operations.

    In the wake of this exposure, it is imperative that organizations assess their cybersecurity defenses and ensure they include EDR solutions that can detect and respond to such threats effectively. Awareness about the tactics employed by malicious actors and utilizing tools designed to identify potential vulnerabilities will also be vital in preventing similar incidents in the future.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Brickstorm-Malware-Scandal-A-Long-Term-Spy-Operation-Targeting-US-Organizations-ehn.shtml

  • https://www.bleepingcomputer.com/news/security/google-brickstorm-malware-used-to-steal-us-orgs-data-for-over-a-year/

  • https://www.bleepingcomputer.com/news/security/google-brickstone-malware-used-to-steal-us-orgs-data-for-over-a-year/

  • https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign

  • https://www.justice.gov/opa/pr/justice-department-charges-12-chinese-contract-hackers-and-law-enforcement-officers-global

  • https://www.reuters.com/technology/cybersecurity/apt31-chinese-hacking-group-behind-global-cyberespionage-campaign-2024-03-26/

  • https://thehackernews.com/2025/09/unc5221-uses-brickstorm-backdoor-to.html

  • https://medium.com/@scottbolen/mitre-attunes-spotlight-on-unc5221-decoding-chinas-apt-with-recent-attack-findings-2c3e7781c73b


  • Published: Wed Sep 24 13:35:49 2025 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us