Suspected China-linked threat group UNC5221 has infiltrated numerous U.S. organizations in the legal, technology, SaaS, and business process outsourcing sectors using the BRICKSTORM backdoor. The campaign, uncovered by Google Threat Intelligence and Mandiant, has enabled persistent access for over a year, with attackers remaining undetected for an average of 393 days. BRICKSTORM, a Go-based malware, provides extensive capabilities including web server setup, file manipulation, command execution, and acting as a SOCKS relay, and is often deployed on appliances lacking endpoint detection and response (EDR) support. The attackers have leveraged these intrusions to steal intellectual property, gather intelligence on national security and trade, and potentially develop new zero-day exploits, with evidence suggesting exploitation of edge device vulnerabilities such as those in Ivanti products. The campaign's stealth and focus on high-value targets raise concerns about long-term impacts and the potential for further downstream compromises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
CISA released a Malware Analysis Report for the BRICKSTORM backdoor, providing official U.S. government technical analysis of the malware. The report added authoritative technical details and indicators to support defender detection and response for BRICKSTORM activity.
Alongside the public disclosure, Mandiant released a free scanner script for Linux/BSD appliances based on BRICKSTORM YARA logic and shared YARA rules for related malware. The company warned the tooling was not comprehensive and would not assess persistence mechanisms or whether devices remained vulnerable.
On September 24, 2025, Google and Mandiant publicly disclosed the BRICKSTORM espionage campaign and attributed it to the China-linked UNC5221 cluster. They described use of stealthy command-and-control traffic masquerading as services such as Cloudflare and Heroku, along with post-compromise tools including Bricksteal and Slaystyle.
Mandiant and Google reported that BRICKSTORM intrusions often remained undetected for over a year, with an average dwell time of 393 days. The malware was observed on Linux/BSD appliances and VMware vCenter/ESXi systems that typically lack EDR coverage, helping the actor evade enterprise defenses.
On 2025-09-22, Mandiant published a standalone Bash-based BRICKSTORM IOC scanner for Linux and BSD systems on GitHub. The tool replicated logic from the G_APT_Backdoor_BRICKSTORM_3 YARA rule as a best-effort detector and warned it would not detect all variants or assess persistence or vulnerability status.
Since at least March 2025, Mandiant said it had responded to numerous UNC5221 intrusions affecting U.S. law firms, SaaS providers, and technology companies. The campaign focused on stealing intellectual property and accessing senior leaders' email inboxes while maintaining persistence in poorly monitored edge and virtualization environments.
Investigators determined that at least one of the BRICKSTORM-linked compromises involved exploitation of a zero-day vulnerability in Ivanti Connect Secure. Mandiant assessed edge-device zero-day exploitation as a likely initial access method more broadly, although long dwell times and missing logs limited confirmation in many cases.
Google Threat Intelligence Group said it documented the Go-based BRICKSTORM backdoor in April 2024 after observing China-related intrusions that appeared to originate from edge devices. The malware was designed for stealthy long-term access, data theft, file operations, payload delivery, SOCKS relaying, and remote command execution.
14 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcehackread.com
Open sourcego.theregister.com
Open sourcegovinfosecurity.com
Open sourcegithub.com
Open sourcenviso.eu
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.