A China-linked cyber-espionage group, tracked as UNC5221, has been systematically targeting network and infrastructure appliances that lack traditional endpoint detection and response (EDR) capabilities. The group has deployed a sophisticated backdoor, known as 'Brickstorm,' to enable persistent, long-term access to compromised environments. According to Google’s Threat Intelligence Group (GTIG), the campaign has affected organizations across various sectors, including legal services, technology, software-as-a-service (SaaS) providers, and business process outsourcing. The attackers have exploited the lack of EDR support on edge devices, making detection and remediation particularly challenging. Brickstorm is designed to evade detection by mimicking legitimate software and using unique command-and-control (C2) servers for each victim, which complicates efforts to block or track the malware. The average dwell time for the attackers within victim networks has been reported as 393 days, indicating a high level of stealth and operational security. During this time, UNC5221 has been observed accessing sensitive emails belonging to developers, administrators, and other individuals of strategic interest, often by abusing Microsoft Entra ID enterprise applications with elevated permissions. The campaign has also resulted in the compromise of SaaS providers, which in turn has led to downstream access to their customers’ environments, amplifying the potential impact. The attackers have targeted leading network appliances from vendors such as SonicWall, Cisco, and Palo Alto Networks, highlighting the breadth of the campaign. GTIG reports that the threat actors have used their access to steal proprietary source code and other intellectual property related to enterprise technologies, which may be analyzed to discover new vulnerabilities for future exploitation. The campaign’s focus on long-term, undetected access distinguishes it from other Chinese-linked espionage operations, such as RedNovember, which prioritizes speed and scale over stealth. Security experts note that the strategic aim of these campaigns is to gain intelligence and maintain persistent access to high-value targets globally. The use of unique C2 infrastructure for each victim further complicates incident response and attribution. The campaign’s ability to remain undetected for over a year in some environments underscores the need for improved monitoring and security controls on edge devices and network appliances. The targeting of organizations with access to downstream customers raises concerns about supply chain risks and the potential for widespread secondary compromise. Researchers emphasize that the attackers’ analysis of stolen source code could lead to the discovery of zero-day vulnerabilities, increasing the threat to enterprise technology products worldwide. The campaign demonstrates the evolving tactics of Chinese APT groups in targeting critical infrastructure and enterprise technologies. Organizations are urged to review their security posture, particularly regarding edge devices and third-party service providers, to mitigate the risk of similar intrusions. The incident highlights the importance of cross-sector collaboration and intelligence sharing to detect and respond to sophisticated, long-term cyber-espionage campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
NSA announced it had joined CISA in releasing guidance on detecting BRICKSTORM backdoor activity. This represents a separate official government response and technical guidance publication related to the campaign.
On September 24, 2025, Recorded Future's Insikt Group published findings on the China-linked RedNovember campaign, also tracked by Microsoft as Storm-2077, which used the Pantegana backdoor and Cobalt Strike to compromise edge devices and high-profile government, defense, and critical infrastructure organizations.
By September 24, 2025, Google Threat Intelligence Group had published research on the Brickstorm campaign, describing a China-linked operation that implanted backdoors on edge devices, maintained access in victim environments for an average of 393 days, and focused on long-term espionage and intellectual property theft.
5 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourceaustinlarsen.me
Open sourcensa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.