Dossier
Brickstorm
Coverage of Brickstorm in the Nexus archive.
- VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
VerdantBamboo, a China-nexus cyber espionage group, has deployed a BSD variant of the BRICKSTORM backdoor along with PLENET (GRIMBOLT) and AGENTPSD malware to target Linux systems. Volexity attributed this activity to VerdantBamboo, noting overlaps with the Clay Typhoon (Microsoft) hacking group.
- Chinese APT deploys new malware to keep access to hacked networks
A Chinese espionage group named UNC5221 is using new malware, including Brickstorm, Plenet, and AgentPSD, to maintain access to hacked Microsoft 365 environments.