People’s Republic of China (PRC) state-sponsored cyber actors have been observed deploying the sophisticated BRICKSTORM backdoor malware to maintain long-term, stealthy access within government and information technology sector networks. BRICKSTORM targets both VMware vSphere and Windows environments, employing advanced evasion techniques such as multiple layers of encryption, DNS-over-HTTPS, and a SOCKS proxy for lateral movement. The malware is designed for persistence, with self-monitoring features that allow it to automatically reinstall or restart if disrupted, and has been linked to intrusions where attackers leveraged legitimate credentials and exfiltrated sensitive data from compromised systems.
CISA, NSA, and the Canadian Centre for Cyber Security have jointly released detailed analysis and detection guidance for BRICKSTORM, including indicators of compromise (IOCs), YARA and Sigma rules, and technical breakdowns of eight malware samples. Organizations in government and critical infrastructure sectors are urged to use these resources to detect and respond to BRICKSTORM infections, and to report any related activity to authorities. The campaign highlights the evolving capabilities of PRC state-sponsored actors and the need for robust monitoring and incident response in targeted sectors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Following the joint advisory, multiple reports said private-sector researchers linked related BRICKSTORM activity to China-nexus clusters including UNC5221 and WARP PANDA. The reporting connected the malware to broader espionage operations involving edge-device exploitation, cloud abuse, and long-term persistence.
On December 4, 2025, CISA, NSA, and the Canadian Centre for Cyber Security published a joint warning and malware analysis report on BRICKSTORM. The release included analysis of eight samples and variants, indicators of compromise, YARA and Sigma rules, and mitigation guidance for affected sectors.
CISA's malware analysis said the implant maintained access in victim environments from at least April 2024 through September 2025. This indicates the campaign remained active and undetected in some networks for well over a year.
Mandiant reported responding to numerous BRICKSTORM intrusions since March 2025 across legal, SaaS, and technology organizations. It said the operations sought intellectual property and sensitive data, including senior leaders' email inboxes.
CrowdStrike attributed 2025 BRICKSTORM intrusions against U.S. legal, technology, and manufacturing firms to a China-nexus group it calls WARP PANDA. The company assessed the activity as likely supporting PRC intelligence collection.
During the investigated intrusion, the actors later compromised domain controllers and an ADFS server after establishing access in VMware infrastructure. They exported cryptographic keys and harvested Active Directory data to deepen persistence and access.
CISA and partner reporting said BRICKSTORM activity was observed from at least April 2024 through September 2025, affecting government, IT, legal, SaaS, technology, and other sectors. The malware enabled long-term persistence, credential theft, lateral movement, and data access in VMware and Windows environments.
In one confirmed incident, PRC state-sponsored actors first compromised a DMZ web server in April 2024 and then moved laterally to an internal VMware vCenter server, where they deployed BRICKSTORM. This marked the start of a long-term intrusion used to maintain stealthy access.
CrowdStrike said the China-nexus group it tracks as WARP PANDA has targeted U.S. organizations since at least late 2023, focusing on VMware vCenter and cloud environments. The activity included use of the BRICKSTORM malware family and related implants for covert persistence and data theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
austinlarsen.me
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcecsoonline.com
Open sourcecyberscoop.com
Open sourcebankinfosecurity.com
Open sourcedarkreading.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.