The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released details of a backdoor dubbed BRICKSTORM, which has been used by state-run hackers in the People's Republic of China (PRC) to maintain a long-term presence on compromised systems.
See also: Chinese hackers APT31 target Russian IT companies

Written in Golang, the custom implant essentially gives malicious users interactive access to the system and allows them to browse, upload, download, create, delete, and manipulate files.
The malware, which is primarily used in attacks targeting governments and the information technology (IT) sector, also supports multiple protocols, including HTTPS, Web Sockets , and embedded Transport Layer Security (TLS) for command and control (C2), DNS-over-HTTPS (DoH) to obfuscate communications and integrate with regular traffic, and can act as a SOCKS to facilitate lateral traffic.
The cybersecurity agency did not disclose how many government agencies were affected or what kind of data was stolen. The activity represents an ongoing tactic by Chinese hacking groups, which continue to attack network devices to compromise networks and cloud infrastructure.
In a statement shared with Reuters, a spokesperson for the Chinese embassy in Washington rejected the accusations, saying the Chinese government does not “encourage, support or consent to cyberattacks.”
See also: Chinese APT24 distributes BADAUDIO malware

BRICKSTORM was first documented by Google Mandiant in 2024 in attacks linked to the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (CVE-2023-46805 and CVE-2024-21887). The malware has been attributed to two groups tracked as UNC5221 and a new Chinese-linked adversary tracked by CrowdStrike as Warp Panda.
Earlier in September, Mandiant and the Google Threat Intelligence Group (GTIG) reported that they observed legal services, software-as-a-service (SaaS) providers, business process outsourcing (BPOs), and technology sectors in the US being targeted by UNC5221 and other closely related threat activity groups to deliver malware.
A key characteristic of the malware, according to CISA, is its ability to reinstall or restart itself automatically through a self-monitoring function that allows it to continue operating despite potential interruptions.
See also: Chinese hackers abuse Anthropic's AI model Claude

CISA reported that the attackers also moved laterally from the web server using Server Message Block (SMB) to two hop servers and an Active Directory Federation Services (ADFS), extracting cryptographic keys from the latter. Access to vCenter ultimately allowed the adversary to deploy BRICKSTORM after their privileges were elevated.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
