GRIMBOLT is a C# backdoor associated with the suspected China-nexus threat cluster UNC6201. It emerged as a newer successor to BRICKSTORM and was observed replacing older BRICKSTORM binaries during intrusions from September 2025 onward. The malware is compiled using native ahead-of-time compilation and packed with UPX, a combination intended to improve execution on resource-constrained appliances while reducing the .NET metadata and other artifacts that typically aid static analysis and reverse engineering.
GRIMBOLT has been used as a persistent foothold on compromised enterprise infrastructure, particularly Dell RecoverPoint for Virtual Machines appliances and related VMware environments. It provides remote shell capability and supports command-and-control communications, including WebSocket-based C2, while reusing infrastructure previously associated with BRICKSTORM. In observed operations, UNC6201 deployed GRIMBOLT after exploiting CVE-2026-22769 in Dell RecoverPoint for Virtual Machines, alongside other tooling such as the SLAYSTYLE web shell and BRICKSTORM. The broader campaign used the compromised appliances for long-term persistence, lateral movement, and follow-on access into virtualized infrastructure.
GRIMBOLT formed part of a larger post-compromise toolkit used against backup, recovery, and virtualization infrastructure in North American organizations. The surrounding intrusion activity included persistence through modification of legitimate boot-executed scripts, stealthy pivoting inside VMware environments using temporary virtual network interfaces known as Ghost NICs, and covert access controls on compromised vCenter appliances using Single Packet Authorization techniques. GRIMBOLT is best characterized as a stealth-oriented appliance backdoor designed for durable access, remote command execution, and operational continuity in espionage-focused intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On February 17th, 2026, Dell disclosed a maximum severity zero-day vulnerability in Dell RecoverPoint for Virtual Machines. The vulnerability, tracked as CVE-2026-22769 (CVSS: 10), is due to hard coded credentials. A threat actor with knowledge of the credentials could exploit the vulnerability to enable remote access and root-level persistence. CVE-2026-22769 is reported to have been under active exploitation since at least mid-2024. | Following initial access and exploitation of CVE-2026-22769, UNC6201 was observed deploying three different backdoors to enable persistent access: GRIMBOLT: a backdoor written in C# designed to perform efficiently on devices with minimal resources and also be difficult to analyze statically
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following initial access and exploitation of CVE-2026-22769, UNC6201 was observed deploying three different backdoors to enable persistent access: GRIMBOLT: a backdoor written in C# designed to perform efficiently on devices with minimal resources and also be difficult to analyze statically
By September, however, the attackers had replaced Brickstorm with Grimbolt, a more advanced malware that’s harder to detect... replacing older Brickstorm binaries with the new backdoor that’s more difficult to reverse engineer.
"Carmakal said they observed the hackers using a novel backdoor they named GRIMBOLT."
By September, however, the attackers had replaced Brickstorm with Grimbolt, a more advanced malware that’s harder to detect... replacing older Brickstorm binaries with the new backdoor that’s more difficult to reverse engineer.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local .
An unauthenticated remote attacker who leverages the hardcoded credential can gain root-level access and establish persistent control
the bug, tracked as CVE-2026-22769, was used to deploy a newer version of the Brickstorm backdoor malware that GTIG now calls Grimbolt
UNC6201 (suspected China-nexus) exploited CVE-2026-22769 to compromise Dell RecoverPoint for VMs appliances, deploying the SLAYSTYLE web shell, BRICKSTORM backdoor, and GRIMBOLT, a C#-based backdoor with native AOT compilation to complicate detection.
execute commands as root on the appliance to drop the BRICKSTORM backdoor and its newer version dubbed GRIMBOLT
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local .
An unauthenticated remote attacker who leverages the hardcoded credential can gain root-level access and establish persistent control
execute commands as root on the appliance to drop the BRICKSTORM backdoor and its newer version dubbed GRIMBOLT
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
GRIMBOLT is written in C# and compiled using Native Ahead-of-Time (AOT) compilation... removing Common Intermediate Language (CIL) metadata that security tools typically scan. The malware is further packed with UPX to complicate static analysis.
"they noticed the systems were communicating with hacker-controlled command and control servers associated with BRICKSTORM and GRIMBOLT backdoors"
"GRIMBOLT established WebSocket-based C2 communications: 149.248.11.71 wss://149.248.11.71/rest/apisession"
The attackers employ a stealthy traffic management technique known as Single Packet Authorization (SPA) using iptables... When this magic packet is detected, the source IP address is added to an allowlist.
deploy additional malware to a Synology Network Attached Storage (NAS) appliance
GRIMBOLT... provides a remote shell capability and uses the same command and control as previously deployed BRICKSTORM payload.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Native backdoor delivered by UNC6201 via exploitation of Dell RecoverPoint for Virtual Machines zero-day CVE-2026-22769.
A C#-based backdoor with native AOT compilation used by UNC6201 to complicate detection on compromised Dell RecoverPoint for VMs appliances.
VMware 백업·복구 인프라 침해 후 배포된 백도어로, 복구 체계 무력화와 지속적 접근에 사용된다.
Backdoor deployed against VMware backup and recovery infrastructure to neutralize recovery systems after exploitation of Dell RecoverPoint for Virtual Machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.