HomeSecurityChinese hackers exploited vulnerability in Dell RecoverPoint

Chinese hackers exploited vulnerability in Dell RecoverPoint

For the past 18 months, a Chinese cyber-espionage group has been exploiting a previously unknown vulnerability in Dell RecoverPoint for Virtual Machines, a disaster recovery solution for VMs. The vulnerability, patched by Dell this week, allows unauthenticated attackers to execute commands on the underlying operating system as root.

Dell RecoverPoint

Dell RecoverPoint: Vulnerability CVE-2026-22769

The vulnerability, tracked as CVE-2026-22769, stems from hardcoded admin credentials for the Apache Tomcat Manager. These can be exploited to deploy malicious WAR (Web Application Archive) files . Apache Tomcat is a web server for Java-based web applications.

Researchers from Google's Mandiant team discovered the critical vulnerability while investigating multiple compromised Dell RecoverPoint for Virtual Machines instances in a customer environment that were sending command-and-control (C2) traffic, which was associated with two backdoors known as BRICKSTORM and GRIMBOLT . These backdoors are used by a China-linked APT group that Mandiant tracks as UNC6201 (known for targeting VMware enterprise infrastructure).

See also: Mozilla Firefox: Fixes “Heap Buffer Overflow” vulnerability

Dell RecoverPoint for Virtual Machines is a data replication and protection appliance for VMware environments, making it an attractive target for this group. The new vulnerability affects versions 5.3 SP4 P1, 6.0, 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2, 6.0 SP2, 6.0 SP2 P1, 6.0 SP3 and 6.0 SP3 P1. Customers are advised to upgrade to the patched version 6.0.3.1 HF1. In case the update is not possible, Dell has also released a remediation script.

From BRICKSTORM to GRIMBOLT

UNC6201's activities overlap significantly with another group that Mandiant and Google's GTIG are tracking as UNC5221. This group is known for targeting network devices with zero-day vulnerabilities. Other security firms attribute this activity to the Chinese state-run hacking group Silk Typhoon or APT27, but Google believes it is a different threat actor.

UNC5221 has compromised the networks of US law firms, SaaS providers, external business process partners, and technology companies and has deployed the Linux backdoor BRICKSTORM and a web shell called SLAYSTYLE.

Both BRICKSTORM and SLAYSTYLE have also been observed in the new Dell RecoverPoint attributed to UNC6201. However, the threat actor also deployed a new backdoor called GRIMBOLT.

Graphican backdoor

“GRIMBOLT is a backdoor written in C# that is compiled using native ahead-of-time (AOT) compilation and packaged with UPX,” Mandiant researchers said. “It provides remote shell capability and uses the same command and control as BRICKSTORM.”

See also: Notepad++ fixes update mechanism used to distribute malware

There is evidence that UNC6201 has been exploiting CVE-2026-22769 since mid-2024 to deploy the SLAYSTYLE web shell. However, the replacement of BRICKSTORM with GRIMBOLT did not occur until September 2025. It is unclear whether this was the result of a planned iteration or a reaction to the BRICKSTORM disclosure by Mandiant.

New techniques

In addition to the payloads themselves, the research also uncovered new techniques. For example, the legitimate shell script convert_hosts.sh present on these devices has been modified to include the path to the backdoors to achieve persistence.

The SLAYSTYLE web shell, which is designed to receive commands over HTTP and execute them on the system, was used to create proxy rules via the Linux iptables utility . Specifically, incoming traffic on port 443 (HTTPS), containing a specific HEX string, was silently redirected to port 10443 for the next 5 minutes.

Another new technique was to create temporary network ports on existing virtual machines on VMware ESXi servers, to access other services within the environments.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Zimbra patches XSS, XXE & LDAP Injection vulnerabilities

Chinese hackers exploited vulnerability in Dell RecoverPoint

Charles Carmakal, CTO at Mandiant, described the technique on LinkedIn as “deploying ghost NICs on virtual machines to evade defenders,” because it let researchers hunt for network activity from IP addresses that no longer existed and had never been documented.

Dell recommends deploying RecoverPoint for VMs within a trusted, access-controlled network behind appropriate firewalls and segregation, not on publicly accessible infrastructure. Meanwhile, Mandiant's blog post includes breach indicators and YARA detection rules for the new GRIMBOLT and SLAYSTYLE payloads.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS