BRICKSTORM Backdoor: UNC5221 PRC-Nexus APT Targeting VMware vSphere Infrastructure

BRICKSTORM Backdoor (TL-2026-0313), also tracked as BRICKSTORM Campaign, is a critical-severity malware campaign scored CVSS 9.8, first published 2026-04-02. It is attributed to UNC5221 (China) with high confidence, affects VMware vCenter Server, references 2 CVEs (CVE-2023-46805, CVE-2024-21887), maps to 19 MITRE ATT&CK techniques (T1003, T1007, T1021), and is covered by 9 detection rules and 41 indicators of compromise.

Key facts for TL-2026-0313

Threat ID
TL-2026-0313
Also known as
BRICKSTORM Campaign, Operation BRICKSTORM
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
MALWARE
First published
2026-04-02
Last reviewed
2026-04-02
Attribution
UNC5221
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
legal-services, technology, saas-providers, business-process-outsourcing, government-services, critical-infrastructure, financial
Target regions
North America, Europe, United States, Canada
Detection rules
9
Indicators of compromise
41

Malware and tooling in BRICKSTORM Backdoor

Malware and tooling: BEEFLUSH, BRICKSTEAL, BRICKSTORM - S9015, SLAYSTYLE, Cloudflare Workers, Heroku

PRC state-sponsored threat actor UNC5221 deploys BRICKSTORM, a Go/Rust-based cross-platform backdoor targeting VMware vSphere (vCenter, ESXi), Linux, Windows, and BSD systems. CISA/NSA/CCCS joint advisory AR25-338A (updated Feb 2026) documents 12+ analyzed samples. The campaign achieves an average dwell time of 393 days, targeting US legal, technology, SaaS, and BPO sectors, as well as European critical infrastructure, for long-term espionage operations.

How BRICKSTORM Backdoor works

BRICKSTORM is a sophisticated, modular backdoor attributed to UNC5221, a China-nexus advanced persistent threat (APT) cluster tracked by Mandiant/Google Cloud Threat Intelligence. The malware is written in Go (with newer Rust-based variants identified in December 2025) and is designed for deployment on network appliances and virtualization infrastructure that typically lack traditional endpoint detection and response (EDR) coverage.

The backdoor provides extensive capabilities including: acting as a web server, file system and directory manipulation (upload/download), shell command execution, and SOCKS proxy relay functionality. BRICKSTORM communicates with command-and-control (C2) infrastructure via WebSockets over TLS, employing multiple layers of encryption including nested TLS channels and DNS-over-HTTPS (DoH) to resolve C2 domains. The malware leverages legitimate cloud services — Cloudflare Workers and Heroku applications — for C2 infrastructure, with unique domains per victim to frustrate tracking.

The BRICKSTORM ecosystem includes several companion tools: BRICKSTEAL, a malicious Java Servlet filter deployed on Apache Tomcat that intercepts vCenter web login requests to capture credentials from HTTP Basic authentication headers; SLAYSTYLE (tracked by MITRE as BEEFLUSH), a JSP web shell that executes arbitrary OS commands via HTTP requests; and custom in-memory droppers that modify runtime configurations without touching disk.

UNC5221 gains initial access by exploiting public-facing edge appliances, notably Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887) and VMware management interfaces. Post-compromise, the actor achieves persistence through modification of systemd units, init.d scripts, rc.local files, and PATH hijacking. The group employs sophisticated lateral movement techniques including VM cloning of Domain Controllers and Identity Providers for offline credential extraction (NTDS.dit), SSH-based movement using harvested credentials, and abuse of Microsoft Entra ID Enterprise Applications with mail.read or full_access_as_app scopes for email exfiltration.

The campaign has been active since at least November 2022 targeting European Windows environments, with multiple US intrusions responded to since March 2025. BRICKSTORM samples use Garble obfuscation and XOR cipher encryption to hide key strings including DoH server addresses. The malware includes self-healing persistence mechanisms with delayed-start logic that can postpone C2 communication for months following incident response activity. Across all investigations, no C2 domain or malware sample reuse has been observed across victims, indicating exceptionally high operational security.

CISA, NSA, and the Canadian Centre for Cyber Security (CCCS) have released three iterations of Malware Analysis Report AR25-338A (December 4, 2025; December 19, 2025; February 11, 2026) analyzing 12+ BRICKSTORM samples with YARA and Sigma detection rules. Mandiant has also released a free BRICKSTORM scanner script on GitHub for Linux and BSD appliances.

MITRE ATT&CK techniques used in TL-2026-0313

credential-access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores

discovery

T1007 System Service Discovery

lateral-movement

T1021 Remote Services

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts

persistence

T1037 Boot or Logon Initialization Scripts; T1505 Server Software Component; T1547 Boot or Logon Autostart Execution

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter

command-and-control

T1071 Application Layer Protocol; T1090 Proxy; T1572 Protocol Tunneling

collection

T1114 Email Collection

initial-access

T1190 Exploit Public-Facing Application

stealth

T1574 Hijack Execution Flow

Affected products and versions in BRICKSTORM Backdoor

  • VMware — vCenter Server
    Vulnerable versions: 7.x; 8.x
    Fixed in: Latest patched versions
  • VMware — ESXi
    Vulnerable versions: 7.x; 8.x
    Fixed in: Latest patched versions
  • VMware — Aria Automation Orchestrator
    Vulnerable versions: All versions
    Fixed in: Latest patched versions
  • Ivanti — Connect Secure
    Vulnerable versions: 9.x; 22.x
    Fixed in: 22.7R2.5+
  • Ivanti — Policy Secure
    Vulnerable versions: 9.x; 22.x
    Fixed in: 22.7R1.2+
  • Multiple — Linux Servers
    Vulnerable versions: All distributions running affected infrastructure
  • Microsoft — Windows Server
    Vulnerable versions: 2016; 2019; 2022
  • Multiple — BSD Systems
    Vulnerable versions: FreeBSD, OpenBSD variants on network appliances

Remediation for BRICKSTORM Backdoor

Patches

  • Apply Ivanti Connect Secure patches for CVE-2023-46805 and CVE-2024-21887
  • Update VMware vCenter, ESXi, and Aria Automation Orchestrator to latest security releases
  • Ensure all edge appliances (F5, Fortinet, Citrix) are patched to current versions

Immediate actions

  • Scan all VMware vSphere infrastructure (vCenter, ESXi, Aria) using Mandiant brickstorm-scanner from GitHub
  • Monitor for anomalous DNS-over-HTTPS traffic to public resolvers (1.1.1.1, 8.8.8.8, 9.9.9.9)
  • Audit systemd units, init.d scripts, and rc.local for unauthorized modifications
  • Review all VM cloning activity in vCenter for unauthorized operations
  • Block known BRICKSTORM file hashes at endpoint and network perimeter
  • Inspect /etc/sysconfig/ and /opt/vmware/sbin/ for masqueraded binaries

Workarounds

  • Restrict management interface access to dedicated jump hosts with MFA
  • Disable SSH on ESXi hosts when not actively required for maintenance
  • Implement IP allowlisting for vCenter VAMI interface access
  • Monitor and alert on creation of local accounts via VAMI interface

Longer-term hardening

  • Deploy EDR solutions on all vSphere management hosts and appliances
  • Implement network segmentation isolating vSphere management interfaces from general network traffic
  • Enable enhanced logging for vCenter operations including VM cloning and SSH access
  • Deploy behavioral detection for WebSocket C2 traffic patterns and SOCKS proxy activity
  • Implement certificate pinning and TLS inspection for outbound connections from management infrastructure
  • Conduct regular threat hunts focusing on init.d/systemd persistence and PATH hijacking
  • Review and restrict Microsoft Entra ID Enterprise Application permissions (mail.read, full_access_as_app)

CVEs associated with BRICKSTORM Backdoor

CVE-2023-46805, CVE-2024-21887

Weaknesses (CWE) in BRICKSTORM Backdoor

CWE-78, CWE-287, CWE-306, CWE-502

Timeline of BRICKSTORM Backdoor

  • Earliest known BRICKSTORM deployments targeting Windows environments in Europe identified by Mandiant retrospective analysis
  • UNC5221 begins exploitation of CVE-2023-46805 (Ivanti Connect Secure authentication bypass) for initial access to edge appliances
  • UNC5221 chains CVE-2024-21887 (Ivanti Connect Secure command injection) with CVE-2023-46805 for full remote code execution on target appliances
  • Mandiant identifies UNC5221 pivoting from edge appliances to VMware vSphere infrastructure (vCenter, ESXi) for deeper network access
  • Multiple intrusions discovered during incident response engagements; Mandiant/Google responds to BRICKSTORM compromises at US legal, tech, and SaaS organizations
  • NVISO publishes independent technical analysis of BRICKSTORM espionage backdoor with detailed IOCs and YARA detection rules
  • Mandiant releases brickstorm-scanner tool on GitHub for detecting BRICKSTORM, BRICKSTEAL, and SLAYSTYLE on Linux/BSD appliances
  • Google Cloud Threat Intelligence publishes 'Another BRICKSTORM' blog detailing full campaign analysis; SOC Prime and Picus Security release detection guidance
  • CISA/NSA/CCCS publish joint Malware Analysis Report AR25-338A with 8 Go-based BRICKSTORM samples, YARA rules, and Sigma detection signatures
  • CISA releases MAR-2512217.c1.v2 update adding 3 new samples including first Rust-based BRICKSTORM variants, expanding detection coverage
  • CISA publishes MAR-261234.c1.v1 with additional variant analysis and updated IOCs, confirming ongoing campaign activity
  • Google Cloud publishes comprehensive vSphere and BRICKSTORM Defender Guide with updated detection and remediation guidance for infrastructure teams
  • As of 2026-05-29, BRICKSTORM/UNC5221 remains a live PRC espionage threat: CISA/NSA/CCCS updated MAR AR25-338A on Feb 11, 2026 with a new variant, and Google Cloud issued a vSphere defender guide Apr 2, 2026. No takedown or arrests; actor tooling, infra, and Ivanti KEV CVEs still actively exploited.

Sources cited for BRICKSTORM Backdoor

Threats related to BRICKSTORM Backdoor

Detection coverage for TL-2026-0313

As of 2026-04-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0313 across Splunk SPL, Microsoft KQL and Sigma, covering 41 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats