Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon, BRICKSTORM/GRIMBOLT/SLAYSTYLE, VMware Ghost NIC Pivoting, iptables SPA

Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) (TL-2026-0123), also tracked as DSA-2026-079, is a critical-severity zero-day vulnerability scored CVSS 10, first published 2026-02-21. It is attributed to UNC6201 (China) with high confidence, affects Dell RecoverPoint for Virtual Machines, references 1 CVE (CVE-2026-22769), maps to 30 MITRE ATT&CK techniques (T1003.003, T1021.001, T1021.004), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-0123

Threat ID
TL-2026-0123
Also known as
DSA-2026-079, Operation BRICKSTORM
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
MONITORING
Category
ZERO_DAY
First published
2026-02-21
Last reviewed
2026-02-21
Attribution
UNC6201
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
technology, legal, saas, government, business-process-outsourcing, critical-infrastructure, virtualization-infrastructure
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
23

Malware and tooling in Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

Malware and tooling: BRICKSTEAL, BRICKSTORM - S9015, GRIMBOLT, SLAYSTYLE

Mandiant/GTIG discovered zero-day exploitation of CVE-2026-22769 (CVSS 10.0) in Dell RecoverPoint for Virtual Machines by UNC6201, a suspected PRC-nexus threat cluster with overlaps to Silk Typhoon. Hard-coded Tomcat Manager credentials enable unauthenticated WAR file deployment leading to root-level RCE. Active exploitation since mid-2024 deploying SLAYSTYLE webshells, BRICKSTORM backdoors, and a novel GRIMBOLT C# native AOT backdoor. Actor pivots into VMware infrastructure via Ghost NICs and iptables Single Packet Authorization.

How Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) works

CVE-2026-22769 is a critical hardcoded credential vulnerability (CWE-798) in Dell RecoverPoint for Virtual Machines, all versions prior to 6.0.3.1 HF1. The vulnerability resides in the Apache Tomcat Manager configuration file (/home/kos/tomcat9/tomcat-users.xml), which contains hard-coded default credentials for the 'admin' user. An unauthenticated remote attacker with knowledge of these credentials can authenticate to the Tomcat Manager interface and deploy malicious WAR files via the /manager/text/deploy endpoint, achieving arbitrary code execution as root on the underlying appliance operating system.

Mandiant and Google Threat Intelligence Group (GTIG) identified this vulnerability during incident response engagements where Dell RecoverPoint for Virtual Machines appliances had active command-and-control (C2) beacons associated with BRICKSTORM and GRIMBOLT backdoors. The earliest confirmed exploitation dates to mid-2024, indicating approximately 8 months of zero-day exploitation before public disclosure.

The threat actor UNC6201 — a suspected PRC-nexus cluster with notable overlaps to UNC5221 (publicly reported as Silk Typhoon) — exploited CVE-2026-22769 to deploy SLAYSTYLE JSP webshells for initial foothold, then installed BRICKSTORM Go-based backdoors for persistent C2 access. In September 2025, Mandiant observed UNC6201 replacing BRICKSTORM binaries with GRIMBOLT, a novel backdoor written in C# and compiled using .NET native ahead-of-time (AOT) compilation, packed with UPX. Native AOT compilation eliminates Common Intermediate Language (CIL) metadata, complicating static analysis and reverse engineering while enhancing performance on resource-constrained appliance hardware.

GRIMBOLT provides remote shell capability and uses WebSocket-based C2 communication (wss://149.248.11.71/rest/apisession). Persistence is achieved by modifying the legitimate convert_hosts.sh boot script (/home/kos/kbox/src/installation/distribution/convert_hosts.sh), which executes via rc.local at system startup.

Beyond the Dell appliance exploitation, Mandiant documented novel VMware infrastructure pivoting techniques. The actor created temporary 'Ghost NICs' — ephemeral network ports on existing virtual machines running on ESXi servers — to pivot into internal networks and SaaS infrastructure. On compromised vCenter appliances, the actor deployed iptables rules implementing Single Packet Authorization (SPA): monitoring port 443 for a specific hex string trigger, adding the source IP to an approved list, then silently redirecting subsequent traffic to port 10443 for a 300-second window. This SPA mechanism provides a stealthy, time-limited access channel that is extremely difficult to detect with traditional network monitoring.

Dell released Security Advisory DSA-2026-079 on 2026-02-17, with remediation via upgrade to version 6.0.3.1 HF1 or application of a remediation script. The NVD confirmed the CVSS 10.0 score with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. CISA has added CVE-2026-22769 to the Known Exploited Vulnerabilities catalog. The trivial nature of exploitation (hard-coded credentials, no authentication required) combined with the 8-month exploitation window and nation-state actor involvement makes this a highest-priority threat for any organization running Dell RecoverPoint for Virtual Machines.

MITRE ATT&CK techniques used in TL-2026-0123

credential-access

T1003.003 NTDS; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1555 Credentials from Password Stores

lateral-movement

T1021.001 Remote Desktop Protocol; T1021.004 SSH; T1210 Exploitation of Remote Services

defense-evasion

T1027.002 Software Packing; T1027.004 Compile After Delivery; T1036.005 Match Legitimate Resource Name or Location; T1070.006 Timestomp; T1078.001 Default Accounts; T1497.001 System Checks

persistence

T1037.004 RC Scripts; T1505.003 Web Shell

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

discovery

T1046 Network Service Discovery

execution

T1059.004 Unix Shell

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1071.001 Web Protocols; T1071.004 DNS; T1090.003 Multi-hop Proxy; T1572 Protocol Tunneling; T1573.002 Asymmetric Cryptography

collection

T1114.002 Remote Email Collection; T1213.003 Code Repositories

initial-access

T1190 Exploit Public-Facing Application

resource-development

T1583.003 Virtual Private Server; T1584.005 Botnet

Affected products and versions in Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

  • Dell — RecoverPoint for Virtual Machines
    Vulnerable versions: 5.3 SP2; 5.3 SP3; 5.3 SP4; 5.3 SP4 P1; 6.0; 6.0 SP1; 6.0 SP1 P1; 6.0 SP1 P2; 6.0 SP2; 6.0 SP2 P1
    Fixed in: 6.0.3.1 HF1
  • VMware — vCenter Server
    Vulnerable versions: All (lateral movement target)
  • VMware — ESXi
    Vulnerable versions: All (lateral movement target)

Remediation for Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

Patches

  • Upgrade Dell RecoverPoint for VMs to version 6.0.3.1 HF1
  • For version 5.3 SP4 P1: migrate to 6.0 SP3 first, then upgrade to 6.0.3.1 HF1
  • Alternative: apply Dell remediation script per KB article 000426742

Immediate actions

  • Isolate all Dell RecoverPoint for Virtual Machines appliances from network access immediately
  • Block inbound access to Tomcat Manager interface (/manager/) at network perimeter
  • Conduct forensic analysis of /home/kos/auditlog/fapi_cl_audit_log.log for /manager requests
  • Check /var/lib/tomcat9 and /var/cache/tomcat9/Catalina for unexpected WAR files
  • Inspect /home/kos/kbox/src/installation/distribution/convert_hosts.sh for unauthorized modifications
  • Scan for BRICKSTORM and GRIMBOLT binaries using Mandiant YARA rules
  • Check VMware vCenter VPXD logs for unauthorized VM clone operations

Workarounds

  • Run Dell remediation script (DSA-2026-079) if immediate upgrade is not possible
  • Restrict network access to RecoverPoint management interface to trusted administrator IPs only
  • Disable SSH on vCenter and ESXi if not actively required

Longer-term hardening

  • Deploy network segmentation isolating RecoverPoint appliances from VMware management plane
  • Implement strict egress filtering for all appliance management interfaces
  • Enable vSphere lockdown mode and enforce MFA for vCenter web logins
  • Forward all vCenter, ESXi, and appliance logs to centralized SIEM
  • Establish asset inventory covering all edge devices and appliances lacking EDR coverage
  • Enforce execInstalledOnly policy on ESXi hosts
  • Monitor for Ghost NIC creation and unauthorized SSH enablement on vSphere platforms
  • Implement TTP-based hunting for BRICKSTORM/GRIMBOLT activity per Mandiant hunting guide

CVEs associated with Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

CVE-2026-22769

Weaknesses (CWE) in Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

CWE-798

Timeline of Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

  • Earliest confirmed exploitation of CVE-2026-22769 in the wild by UNC6201 deploying BRICKSTORM and SLAYSTYLE on Dell RecoverPoint appliances. Source: https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day/
  • GTIG publishes initial BRICKSTORM espionage campaign research covering UNC5221/Silk Typhoon overlaps, Go-based backdoor, and VMware infrastructure targeting. Source: https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign
  • Mandiant responds to multiple BRICKSTORM intrusions across technology, legal services, SaaS, and BPO sectors. Average dwell time: 393 days.
  • UNC6201 replaces older BRICKSTORM binaries with GRIMBOLT — novel C# native AOT-compiled backdoor packed with UPX — on compromised Dell RecoverPoint appliances. Source: https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day/
  • CISA publishes Analysis Report AR25-338a covering BRICKSTORM VMware compromise activity. Source: https://www.cisa.gov/news-events/analysis-reports/ar25-338a
  • NVD publishes CVE-2026-22769 with CVSS 10.0, CWE-798 classification. Source: https://nvd.nist.gov/vuln/detail/CVE-2026-22769
  • Dell releases RecoverPoint for VMs version 6.0.3.1 HF1 and remediation script to address CVE-2026-22769. Source: https://www.dell.com/support/kbdoc/en-us/000426742
  • Dell publishes Security Advisory DSA-2026-079 disclosing CVE-2026-22769 hardcoded credential vulnerability. Remediation: upgrade to 6.0.3.1 HF1 or apply remediation script. Source: https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079
  • CISA adds CVE-2026-22769 to the Known Exploited Vulnerabilities (KEV) catalog. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22769
  • Mandiant/GTIG publishes detailed technical blog with YARA rules, IOCs, forensic guidance, and Ghost NIC/iptables SPA TTPs. Source: https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day/
  • As of 2026-05-29, CVE-2026-22769 is patched (Dell 6.0.3.1 HF1, 2026-02-17) but remains in CISA KEV and was exploited as a zero-day since mid-2024, so unpatched RecoverPoint appliances stay at risk. The PRC-nexus actor UNC6201 (Silk Typhoon-linked) is operational and undisrupted, evolving tradecraft (GRIMBOLT replacing BRICKSTORM), with Mandiant still urging active hunting.

Sources cited for Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

Threats related to Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

Detection coverage for TL-2026-0123

As of 2026-02-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0123 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats