BRICKSTORM is an espionage-oriented backdoor written in Go, with variants targeting Linux, Windows, and BSD-based systems. It is particularly associated with VMware vCenter servers and ESXi environments, but has also been deployed on enterprise storage appliances and pfSense firewalls. It supports covert, persistent access in long-running intrusions affecting government, information technology, legal services, and manufacturing organizations.
BRICKSTORM provides file management and network tunneling capabilities, including file upload, download, deletion, renaming, and directory enumeration. Variants support SOCKS and HTTP proxying, while analyzed Windows versions can relay TCP, UDP, and ICMP traffic. Some non-Windows variants support shell command execution; analyzed Windows variants lack direct command execution, with operators instead combining network tunnels and valid credentials to access RDP and SMB services. Command-and-control communications use WebSockets, with some variants employing DNS over HTTPS, nested TLS connections, multiplexed sessions, and cloud-hosted front ends to conceal traffic. Persistence has been established through scheduled tasks and modified system startup configurations.
BRICKSTORM is associated with the China-nexus espionage cluster UNC5221, also tracked as WARP PANDA, and with activity attributed to the overlapping VerdantBamboo cluster. The separately tracked China-nexus cluster UNC6201 has also deployed it. Operators install the backdoor after exploiting vulnerabilities or accessing systems with compromised credentials. Documented deployments followed compromises of Ivanti Connect Secure, VMware infrastructure, Dell RecoverPoint for Virtual Machines, and Egnyte Storage Sync environments. Its proxy functionality facilitates lateral movement and allows access to cloud services to appear to originate from trusted victim infrastructure, enabling evasion of network-location-based Conditional Access controls. BRICKSTORM has supported espionage intrusions lasting more than a year.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
WARP PANDA frequently gained initial access by exploiting internet-facing systems, subsequently pivoting into vCenter environments using either valid credentials or by exploiting known vCenter vulnerabilities, including CVE-2024-38812, CVE-2021-22005, and CVE-2023-34048.
WARP PANDA frequently gained initial access by exploiting internet-facing systems, subsequently pivoting into vCenter environments using either valid credentials or by exploiting known vCenter vulnerabilities, including CVE-2024-38812, CVE-2021-22005, and CVE-2023-34048.
WARP PANDA frequently gained initial access by exploiting internet-facing systems, subsequently pivoting into vCenter environments using either valid credentials or by exploiting known vCenter vulnerabilities, including CVE-2024-38812, CVE-2021-22005, and CVE-2023-34048.
On February 17th, 2026, Dell disclosed a maximum severity zero-day vulnerability in Dell RecoverPoint for Virtual Machines. The vulnerability, tracked as CVE-2026-22769 (CVSS: 10), is due to hard coded credentials. A threat actor with knowledge of the credentials could exploit the vulnerability to enable remote access and root-level persistence. CVE-2026-22769 is reported to have been under active exploitation since at least mid-2024. | Following initial access and exploitation of CVE-2026-22769, UNC6201 was observed deploying three different backdoors to enable persistent access: BRICKSTORM: a backdoor written in Go with support for Linux and BSD-based systems and built in SOCKS proxy functionality
BRICKSTORM, first documented last year in connection with the zero-day exploitation of Ivanti Connect Secure zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) against the MITRE Corporation...
BRICKSTORM, first documented last year in connection with the zero-day exploitation of Ivanti Connect Secure zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) against the MITRE Corporation...
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bloomberg later reported that the attackers had infiltrated F5’s network for over 12 months, using custom malware identified as BRICKSTORM.
WARP PANDA has been observed deploying BRICKSTORM, a backdoor malware specifically designed for VMware environments, including VMware vCenter servers and VMware ESXi hypervisors.
Following initial access and exploitation of CVE-2026-22769, UNC6201 was observed deploying three different backdoors to enable persistent access: BRICKSTORM: a backdoor written in Go with support for Linux and BSD-based systems and built in SOCKS proxy functionality
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM... the adversary had compromised an unnamed victim's Egnyte Storage Sync system by exploiting a local privilege escalation flaw to deploy BRICKSTORM.
Mandiant (part of Google Cloud) just published a comprehensive defender’s guide on securing VMware vSphere environments against the BRICKSTORM backdoor and associated malware activity.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
The adversaries relied on persistence mechanisms such as scheduled tasks for execution.
The adversaries relied on persistence mechanisms such as scheduled tasks for execution.
PRC-attributed intrusions increasingly involve the usage of previously unknown vulnerabilities (a.k.a., zero-days) alongside low-noise backdoors such as the hereafter documented BRICKSTORM family.
Annex B lists Masquerading: Masquerade Task or Service under Defensive Evasion.
The BRICKSTORM family resolves its Command & Control servers through DoH (DNS over HTTPS), hindering most network monitoring solutions. | Once BRICKSTORM has the front service IPs ... the backdoor connects to the Command & Control domain over HTTPS ... The backdoor then upgrades the HTTPS connection to a WebSocket.
Annex B lists Application Layer Protocol: Web Protocols under Command and Control.
Similarly, BRICKSTORM resolves its Command & Control domains through public DoH (DNS over HTTPS) providers which encapsulates plaintext DNS messages within secure HTTPS connections.
BRICKSTORM: a backdoor written in Go with support for Linux and BSD-based systems and built in SOCKS proxy functionality
The backdoor’s JSON-based API provides a wide range of file-related actions such as uploading, downloading, renaming, and deleting files.
71 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
138 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware cited as an example of an espionage campaign that remained undetected for nearly 400 days.
CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks
Malware deployed on compromised VMware vSphere servers by Chinese threat actors; associated in the article with post-compromise activity including rogue VM creation and theft of cloned VM snapshots for credential theft.
BRICKSTORM5
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.