GRIMBOLT is a C# backdoor used by the suspected PRC-nexus threat cluster UNC6201 in intrusions involving Dell RecoverPoint for Virtual Machines and subsequent compromise of VMware environments. It emerged as a successor to BRICKSTORM, with investigators observing older BRICKSTORM deployments being replaced by GRIMBOLT in September 2025. The malware is compiled using .NET Native Ahead-of-Time compilation and packed with UPX, a combination that reduces typical managed-code metadata and complicates static analysis and reverse engineering. GRIMBOLT is described as a foothold or persistent backdoor that provides remote shell capability and communicates with command-and-control infrastructure also used by BRICKSTORM. Reporting also associates it with WebSocket-based command-and-control. In the observed campaign, UNC6201 exploited CVE-2026-22769 in Dell RecoverPoint for Virtual Machines to deploy additional tooling including the SLAYSTYLE web shell and BRICKSTORM, then used GRIMBOLT as part of long-term access, lateral movement, and post-compromise operations. The broader activity targeted backup, recovery, and virtualization infrastructure, including VMware environments, and employed stealth techniques such as temporary virtual network interfaces known as Ghost NICs and covert access controls on compromised appliances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Most notably, CVE-2026-22769, a hardcoded credential flaw in Dell RecoverPoint for Virtual Machines, was exploited as a zero day by the PRC linked threat cluster UNC6201 since mid 2024. Google's threat intelligence team documented the actor delivering the BRICKSTORM backdoor, GRIMBOLT native backdoors, and the SLAYSTYLE webshell through this vulnerability. | Google's threat intelligence team documented the actor delivering the BRICKSTORM backdoor, GRIMBOLT native backdoors, and the SLAYSTYLE webshell through this vulnerability.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Google's threat intelligence team documented the actor delivering the BRICKSTORM backdoor, GRIMBOLT native backdoors, and the SLAYSTYLE webshell through this vulnerability.
By September, however, the attackers had replaced Brickstorm with Grimbolt, a more advanced malware that’s harder to detect... replacing older Brickstorm binaries with the new backdoor that’s more difficult to reverse engineer.
"Carmakal said they observed the hackers using a novel backdoor they named GRIMBOLT."
By September, however, the attackers had replaced Brickstorm with Grimbolt, a more advanced malware that’s harder to detect... replacing older Brickstorm binaries with the new backdoor that’s more difficult to reverse engineer.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local .
An unauthenticated remote attacker who leverages the hardcoded credential can gain root-level access and establish persistent control
the bug, tracked as CVE-2026-22769, was used to deploy a newer version of the Brickstorm backdoor malware that GTIG now calls Grimbolt
UNC6201 (suspected China-nexus) exploited CVE-2026-22769 to compromise Dell RecoverPoint for VMs appliances, deploying the SLAYSTYLE web shell, BRICKSTORM backdoor, and GRIMBOLT, a C#-based backdoor with native AOT compilation to complicate detection.
execute commands as root on the appliance to drop the BRICKSTORM backdoor and its newer version dubbed GRIMBOLT
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local .
An unauthenticated remote attacker who leverages the hardcoded credential can gain root-level access and establish persistent control
execute commands as root on the appliance to drop the BRICKSTORM backdoor and its newer version dubbed GRIMBOLT
UNC6201 established BRICKSTORM and GRIMBOLT persistence on the Dell RecoverPoint for Virtual Machines by modifying a legitimate shell script named convert_hosts.sh to include the path to the backdoor. This shell script is executed by the appliance at boot time via rc.local.
GRIMBOLT is written in C# and compiled using Native Ahead-of-Time (AOT) compilation... removing Common Intermediate Language (CIL) metadata that security tools typically scan. The malware is further packed with UPX to complicate static analysis.
"they noticed the systems were communicating with hacker-controlled command and control servers associated with BRICKSTORM and GRIMBOLT backdoors"
"GRIMBOLT established WebSocket-based C2 communications: 149.248.11.71 wss://149.248.11.71/rest/apisession"
The attackers employ a stealthy traffic management technique known as Single Packet Authorization (SPA) using iptables... When this magic packet is detected, the source IP address is added to an allowlist.
deploy additional malware to a Synology Network Attached Storage (NAS) appliance
GRIMBOLT... provides a remote shell capability and uses the same command and control as previously deployed BRICKSTORM payload.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Native backdoor delivered by UNC6201 via exploitation of Dell RecoverPoint for Virtual Machines zero-day CVE-2026-22769.
A C#-based backdoor with native AOT compilation used by UNC6201 to complicate detection on compromised Dell RecoverPoint for VMs appliances.
VMware 백업·복구 인프라 침해 후 배포된 백도어로, 복구 체계 무력화와 지속적 접근에 사용된다.
Backdoor deployed against VMware backup and recovery infrastructure to neutralize recovery systems after exploitation of Dell RecoverPoint for Virtual Machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.