BRICKSTORM is a cross-platform espionage backdoor and remote access trojan associated primarily with the China-nexus threat cluster UNC5221, also tracked as VerdantBamboo, and also observed in activity attributed to UNC6201. It has been used in long-running intrusions against edge appliances, VMware infrastructure, and enterprise systems, including campaigns affecting government, legal, technology, and IT-sector organizations, as well as environments of strategic interest in Europe and the United States.
BRICKSTORM has been described as Go-based in multiple observed variants, with support for Linux, BSD-based systems, and Windows. It has been deployed on VMware vCenter and vSphere-related systems, Egnyte Storage Sync appliances, pfSense firewalls, and other Linux or BSD appliance-like environments that often lack robust endpoint monitoring. Operators have used it to maintain persistent access after exploitation of edge-device and virtualization vulnerabilities, including Ivanti Connect Secure and Dell RecoverPoint for Virtual Machines compromises, and to sustain covert access for extended periods.
Its functionality includes backdoor access, file and directory management, network tunneling and proxying, WebSocket-based command and control, and SOCKS proxy capability. Reported variants support TCP, UDP, and ICMP relaying, and some incidents also attributed shell command execution capability to BRICKSTORM, particularly on VMware-targeted Linux deployments. Windows variants have been observed exposing a file-management interface and tunneling features while relying on valid credentials and native protocols such as RDP and SMB for follow-on operations rather than direct command execution.
BRICKSTORM is notable for stealth-oriented communications design. Observed variants have used DNS over HTTPS for name resolution, layered TLS over WebSocket channels, and session multiplexing to conceal command-and-control traffic and blend into normal encrypted network activity. In victim environments, operators have used BRICKSTORM’s proxying and tunneling features to route access through trusted internal infrastructure, including SSL VPN paths, enabling lateral movement and access to cloud services such as Microsoft 365 while evading policy controls based on source network trust.
Persistence has been established through multiple mechanisms depending on platform, including startup-script modification, scheduled tasks, cron-based execution, and service-style boot persistence on Unix-like systems. The malware has been repeatedly observed as part of broader post-exploitation tradecraft involving credential abuse, long-term persistence, lateral movement, and data theft in espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On February 17th, 2026, Dell disclosed a maximum severity zero-day vulnerability in Dell RecoverPoint for Virtual Machines. The vulnerability, tracked as CVE-2026-22769 (CVSS: 10), is due to hard coded credentials. A threat actor with knowledge of the credentials could exploit the vulnerability to enable remote access and root-level persistence. CVE-2026-22769 is reported to have been under active exploitation since at least mid-2024. | Following initial access and exploitation of CVE-2026-22769, UNC6201 was observed deploying three different backdoors to enable persistent access: BRICKSTORM: a backdoor written in Go with support for Linux and BSD-based systems and built in SOCKS proxy functionality
BRICKSTORM, first documented last year in connection with the zero-day exploitation of Ivanti Connect Secure zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) against the MITRE Corporation...
BRICKSTORM, first documented last year in connection with the zero-day exploitation of Ivanti Connect Secure zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) against the MITRE Corporation...
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following initial access and exploitation of CVE-2026-22769, UNC6201 was observed deploying three different backdoors to enable persistent access: BRICKSTORM: a backdoor written in Go with support for Linux and BSD-based systems and built in SOCKS proxy functionality
This report delivers a comprehensive technical analysis of BRICKSTORM, an espionage backdoor linked to the China-nexus cluster UNC5221.
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM... the adversary had compromised an unnamed victim's Egnyte Storage Sync system by exploiting a local privilege escalation flaw to deploy BRICKSTORM.
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM... the adversary had compromised an unnamed victim's Egnyte Storage Sync system by exploiting a local privilege escalation flaw to deploy BRICKSTORM.
Mandiant (part of Google Cloud) just published a comprehensive defender’s guide on securing VMware vSphere environments against the BRICKSTORM backdoor and associated malware activity.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers may leverage network tunneling to, for example, relay RDP and SMB connections... attackers have been observed deploying BRICKSTORM on domain-joined devices after having obtained valid privileged credentials.
The attacker’s workstation, sitting somewhere outside the victim’s network, connected to the organization’s web-based SSL VPN.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
The adversaries relied on persistence mechanisms such as scheduled tasks for execution.
Attackers may leverage network tunneling to, for example, relay RDP and SMB connections... attackers have been observed deploying BRICKSTORM on domain-joined devices after having obtained valid privileged credentials.
The attacker’s workstation, sitting somewhere outside the victim’s network, connected to the organization’s web-based SSL VPN.
Both versions were given local persistence mechanisms. /mnt/cpt/tmpd was given both /etc/rc.local and /etc/init.d/urandom_seed while /bin/httpd was given /etc/init.d/urandom_seed persistence method.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
The adversaries relied on persistence mechanisms such as scheduled tasks for execution.
PRC-attributed intrusions increasingly involve the usage of previously unknown vulnerabilities (a.k.a., zero-days) alongside low-noise backdoors such as the hereafter documented BRICKSTORM family.
Attackers may leverage network tunneling to, for example, relay RDP and SMB connections... attackers have been observed deploying BRICKSTORM on domain-joined devices after having obtained valid privileged credentials.
Both versions were given local persistence mechanisms. /mnt/cpt/tmpd was given both /etc/rc.local and /etc/init.d/urandom_seed while /bin/httpd was given /etc/init.d/urandom_seed persistence method.
The BRICKSTORM family resolves its Command & Control servers through DoH (DNS over HTTPS), hindering most network monitoring solutions. | Once BRICKSTORM has the front service IPs ... the backdoor connects to the Command & Control domain over HTTPS ... The backdoor then upgrades the HTTPS connection to a WebSocket.
Communicates with its C2 infrastructure over WebSockets, with some variants using DNS-over-HTTPS (DoH) to obscure C2 lookups from standard DNS monitoring
Similarly, BRICKSTORM resolves its Command & Control domains through public DoH (DNS over HTTPS) providers which encapsulates plaintext DNS messages within secure HTTPS connections.
BRICKSTORM: a backdoor written in Go with support for Linux and BSD-based systems and built in SOCKS proxy functionality
The backdoor’s JSON-based API provides a wide range of file-related actions such as uploading, downloading, renaming, and deleting files.
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
134 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks
Malware deployed on compromised VMware vSphere servers by Chinese threat actors; associated in the article with post-compromise activity including rogue VM creation and theft of cloned VM snapshots for credential theft.
BRICKSTORM5
Backdoor delivered by UNC6201 via exploitation of Dell RecoverPoint for Virtual Machines zero-day CVE-2026-22769.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.