VerdantBamboo (UNC5221 / WARP PANDA) BRICKSTORM Campaign — MSP Supply-Chain Compromise of Edge Appliances with 18-Month Dwell — Threadlinqs Intelligence
As of 2026-06-07, VerdantBamboo (UNC5221 / WARP PANDA) BRICKSTORM Campaign — MSP Supply-Chain Compromise of Edge Appliances with 18-Month Dwell is a critical-severity apt threat attributed to VerdantBamboo (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 57 indicators of compromise.
Threat ID: TL-2026-0706 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: VerdantBamboo · China · ESPIONAGE
China-nexus espionage actor VerdantBamboo (UNC5221 / WARP PANDA) maintained access to a U.S. victim network for at least 18 months by compromising the victim's MSP and abusing EDR-less edge
Volexity, in an incident response engagement that began in September 2025, uncovered a long-running intrusion by the China-nexus actor VerdantBamboo (also tracked as UNC5221 and WARP PANDA). The actor had maintained covert access to the victim environment for at least 18 months, deliberately targeting network edge and infrastructure appliances — firewalls, NAS, and storage-sync VMs — that fall outside typical EDR coverage.
INITIAL ACCESS & FOOTHOLD: The earliest confirmed foothold was a Linux Egnyte Storage Sync VM, accessed via valid SSH credentials for the 'egnyteservice' account, reached through the victim's web SSL VPN. A local privilege escalation in Egnyte Storage Sync (sudoers Cmnd_Alias EGNYTEAPPS granting PASSWD-less use of /usr/bin/tee to the unprivileged egnyteservice account) allowed arbitrary file writes anywhere on the filesystem — fixed in Storage Sync v13.13. The actor also compromised the victim's Managed Service Provider (MSP) and planted a BSD-compiled BRICKSTORM variant on the MSP's pfSense firewall, providing a resilient re-entry point.
MALWARE — BRICKSTORM: A modular Golang RAT (with later Rust variants and a FreeBSD build for pfSense) built around the 'wssoft' package namespace (wssoft.core for C2/task dispatch, wssoft.libs for local ops). It communicates over WebSocket and supports pluggable task extensions: 'command' (shell), 'socks' (SOCKS5 proxy), and 'web' (filesystem interface). Instances are customized per victim with only the needed extensions; the BSD variant was obfuscated with gobfuscate. On the Storage Sync host it was placed at /usr/sbin/ (luserput); on the pfSense firewall at /usr/local/libexec/ipsec/blacklist. C2 domains are customized per victim and front through Cloudflare.
MALWARE — AGENTPSD: A PyInstaller-compiled Python reverse shell deployed as /usr/local/bin/egnyte/egnyte_host_monitor_client, assessed (medium confidence) as a fallback. It beacons over HTTPS POST with Content-Type application/octet-stream and a 'sec-fetch-tag' header carrying Base64-encoded system info, identifies clients as root_<hostname>_<hex machine UUID>, uses the hardcoded delimiter PoRaSGw3jzQ8YSaz, Base64 command encoding (ignoring the first character), and supports interval/during/builtin command types. Persistence was a crontab entry firing on the 15th at 14:20. Its C2 domain was registered but never resolved during the investigation.
MALWARE — PLENET (Google: Grimbolt): A cross-platform .NET Core backdoor compiled with Native AOT and packed with UPX, deployed to a Linux-based Synology NAS as ovs-dbctl. It uses WebSocket C2 multiplexed via the Nerdbank.Streams library and native .NET Task async, and supports interactive shell, remote command execution, file manipulation, and live C2 server switching. The .NET/AOT choice is assessed (medium confidence) as an anti-analysis measure.
LATERAL MOVEMENT & OBJECTIVE: BRICKSTORM's SOCKS proxy let the actor tunnel through trusted internal infrastructure to access the victim's Microsoft 365 environment with stolen credentials, blending with legitimate traffic and bypassing Conditional Access IP restrictions. A SLAYSTYLE webshell and additional BRICKSTORM samples were also observed. After Volexity's initial remediation, the actor regained access within days via stolen, MFA-less firewall administrative credentials and an actor-enabled SSL VPN configuration — underscoring incomplete eradication of the MSP foothold.
INFRASTRUCTURE: On 2025-09-06 Volexity built a Censys fingerprint for BRICKSTORM C2 (minimal HTTP response on 443, OpenBSD SSH on 22, Cloudflare-issued certificate, low service count); between 2025-09-18 and 2025-09-23 every matching server disabled its port 443 service, and on 2025-09-24 Google Cloud published its own BRICKSTORM analysis. VerdantBamboo demonstrates strong OPSEC: limited per-victim infrastructure, per-device implant naming/persistence, and a focus on appliances lacking endpoint telemetry.
Weaknesses (CWE)
CWE-269, CWE-250, CWE-732
Target sectors: legal services, saas, business process outsourcing, technology, managed service providers
Target regions: North America, United States
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 57 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1583, T1199, T1078, T1133, T1190, T1059, T1059, T1053, T1505, T1078