Chinese hackers deployed a custom Linux backdoor (BRICKSTORM) on compromised network devices to maintain persistent access to the networks of US law firms, software-as-a-service (SaaS) providers, business process outsourcers, and technology companies.

Most worryingly, on average, the backdoor persisted for 393 days on compromised victims' systems and was used as a launching point for lateral movement to VMware vCenter and ESXi hosts, Windows workstations and servers, and Microsoft 365 mailboxes.
“The value of these targets goes beyond typical espionage missions, potentially providing data for zero-day deployment and establishing pivot points for broader access to downstream victims,” said researchers from Mandiant and Google’s Threat Team.
Researchers attribute these attacks to a group they are tracking as UNC5221, whose activity overlaps with another state-sponsored threat actor from China known as Silk Typhoon. However, Google believes it is a different group.
See also: Chinese Hackers RedNovember Target Global Governments
The team's primary tool is a backdoor written in Go for Linux and BSD devices. Mandiant has named it BRICKSTORM. Most network and other edge devices do not have traditional detection and response tools installed and are generally outside the scope of log monitoring . This makes detecting BRICKSTORM implants very difficult without actively searching for threats, which is why Mandiant has now released a detection script that can be run on devices to look for relevant indicators of compromise.
Initial access is difficult to determine
UNC5221 is the only group known to have exploited the CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure and Ivanti Policy Secure as zero-days, (as of December 2023). However, the BRICKSTORM backdoor has been found on different types of devices from different manufacturers without clear signs of exploitation. In part, this evidence may be missing because the attackers had been around for a long time (over a year) before the intrusions were recognized. This time period exceeds the normal retention periods for internal logs on such devices. And if the logs are not collected and stored in a centralized solution, there is no way to determine how a device was compromised in the first place.

“Despite these challenges, a pattern in the available evidence points to the actor’s focus on breaching the perimeter and remote access infrastructure,” Mandiant researchers found.
Targeting virtual machines
BRICKSTORM has also been found on VMware vCenter and ESXi servers, where it was deployed using valid credentials likely stolen from compromised network devices. The attackers also deployed a Java Servlet filter on the web server running the vCenter web management interface. The filter, dubbed BRICKSTEAL by Mandiant, allowed them to intercept HTTP requests to the login page that might contain usernames and passwords. Users who typically access vCenter have a high level of privilege within the enterprise.
See also: Hackers can compromise Chromium browsers on Windows
Additionally, the attackers deployed a web shell called SLAYSTYLE on vCenter that can receive commands over HTTP and execute them on the system. In other cases, the attackers enabled the SSH service on vCenter via the web interface and then used the SSH access to deploy BRICKSTORM. The attackers also used VMware vCenter to clone existing virtual machines for Windows servers that act as domain controllers, SSO identity providers, and secret vaults. They then mounted the file systems of these virtual machines and extracted credentials stored within. These credentials were used for further lateral movement to other systems.
Theft of mailboxes and codes
A common theme across all the attacks was attackers using Microsoft Entra ID Enterprise Applications with stolen credentials to gain access to Microsoft 365 mailboxes of developers, system administrators, or individuals involved in activities of financial and espionage interest.
BRICKSTORM also acts as a SOCKS proxy , allowing attackers to gain direct access to systems and web applications on the enterprise network. The attackers used this tunneling capability to extract files of interest collected from workstations or archived code repositories.

How the attackers chose their targets
“Recent intrusion operations linked to BRICKSTORM likely represent a range of goals ranging from geopolitical espionage, access operations, and intellectual property theft to enable exploit development,” Google researchers found.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
For example, legal services were likely targeted for gathering information relevant to US national security and trade, while SaaS providers were targeted for their customer data or further access to their customers' environments. Technology companies were targeted for theft intellectual property, but stolen source code could also be analyzed to discover vulnerabilities in their products and develop zero-day exploits.
See also: Atos offers cybersecurity services in Europe
Mandiant's report contains detailed guidance on how organizations should perform threat research that focuses on TTPs rather than IOCs to detect attack patterns. This is because UNC5221 used different BRICKSTORM samples and command and control servers for each individual victim.
“Fundamental to the success of any threat hunt is an asset inventory that includes devices not covered by the standard security toolkit, such as edge devices and other devices,” the researchers found. “Because these devices do not support traditional security tools, an inventory is critical for developing effective countermeasures and detections.”
