Bricksteal is a credential-stealing malware component observed in long-term espionage intrusions attributed by Google Threat Intelligence Group to the UNC5221 cluster, a China-linked threat actor. It was used alongside the BRICKSTORM backdoor and custom droppers in operations targeting U.S. organizations, particularly in the technology and legal sectors, including SaaS providers and BPOs. The malware was deployed in environments that often lack EDR coverage, especially VMware vCenter/ESXi appliances. After attackers established a foothold, Bricksteal was used on vCenter as a malicious Java Servlet Filter to capture credentials and support privilege escalation. Stolen credentials were then used for lateral movement and persistence, alongside related activity such as cloning Windows Server virtual machines to extract secrets, enabling SSH on ESXi, and modifying init.d and systemd startup scripts. The broader intrusion set used stealthy C2 masquerading as legitimate services such as Cloudflare and Heroku, and operators reportedly removed malware after operations to hinder forensics. Mandiant reported YARA rules for Bricksteal as part of its tooling released to help detect related compromises.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After establishing a foothold, the attacker tried to escalate privileges using a malicious Java Servlet Filter (Bricksteal) on vCenter to capture credentials...
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential stealer deployed alongside BRICKSTORM as part of a sophisticated espionage toolkit, used to extract credentials from compromised systems.
Malicious Java Servlet Filter used on VMware vCenter to capture credentials to support privilege escalation, lateral movement, and persistence.
Malicious Java Servlet Filter used on VMware vCenter to capture credentials to support privilege escalation, lateral movement, and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.