The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA) and the Canadian Centre for Cyber Security, has released an updated advisory on the BRICKSTORM backdoor malware. The update includes new indicators of compromise (IOCs), detection signatures, and analysis of three additional malware samples, bringing the total to 11 analyzed variants. Notably, the latest samples include Rust-based variants, highlighting the evolving tactics of the People’s Republic of China (PRC) state-sponsored actors behind BRICKSTORM. The malware is known for targeting government and IT sectors, particularly VMware vSphere environments, and employs advanced persistence, encryption, and defense evasion techniques.
The advisory provides new YARA rules and detection guidance to help organizations identify and respond to BRICKSTORM infections. The malware leverages multiple layers of encryption, such as HTTPS, WebSockets, and DNS-over-HTTPS, to conceal its command-and-control communications and blends malicious activity with legitimate network traffic. Organizations are urged to deploy the updated IOCs and signatures, scan for BRICKSTORM-related activity, and report any detections to CISA for further investigation and response.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The updated advisory published technical details on 11 BRICKSTORM variants and introduced two new YARA detection signatures to help defenders identify infections. Agencies urged organizations, particularly those operating VMware vSphere environments in government and IT sectors, to apply the new detection guidance and report related incidents.
CISA, NSA, and the Canadian Centre for Cyber Security released an updated Malware Analysis Report on the BRICKSTORM backdoor, adding new indicators of compromise and detection signatures. The update covered additional samples, including Rust-based variants with persistence, defense evasion, and encrypted WebSocket command-and-control capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.