For the past 18 months, a Chinese cyber-espionage group has been exploiting a previously unknown vulnerability in Dell RecoverPoint for Virtual Machines, a disaster recovery solution for VMs. The vulnerability, patched by Dell this week, allows unauthenticated attackers to execute commands on the underlying operating system as root.

Dell RecoverPoint: Vulnerability CVE-2026-22769
The vulnerability, tracked as CVE-2026-22769, stems from hardcoded admin credentials for the Apache Tomcat Manager. These can be exploited to deploy malicious WAR (Web Application Archive) files . Apache Tomcat is a web server for Java-based web applications.
Researchers from Google's Mandiant team discovered the critical vulnerability while investigating multiple compromised Dell RecoverPoint for Virtual Machines instances in a customer environment that were sending command-and-control (C2) traffic, which was associated with two backdoors known as BRICKSTORM and GRIMBOLT . These backdoors are used by a China-linked APT group that Mandiant tracks as UNC6201 (known for targeting VMware enterprise infrastructure).
See also: Mozilla Firefox: Fixes “Heap Buffer Overflow” vulnerability
Dell RecoverPoint for Virtual Machines is a data replication and protection appliance for VMware environments, making it an attractive target for this group. The new vulnerability affects versions 5.3 SP4 P1, 6.0, 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2, 6.0 SP2, 6.0 SP2 P1, 6.0 SP3 and 6.0 SP3 P1. Customers are advised to upgrade to the patched version 6.0.3.1 HF1. In case the update is not possible, Dell has also released a remediation script.
From BRICKSTORM to GRIMBOLT
UNC6201's activities overlap significantly with another group that Mandiant and Google's GTIG are tracking as UNC5221. This group is known for targeting network devices with zero-day vulnerabilities. Other security firms attribute this activity to the Chinese state-run hacking group Silk Typhoon or APT27, but Google believes it is a different threat actor.
UNC5221 has compromised the networks of US law firms, SaaS providers, external business process partners, and technology companies and has deployed the Linux backdoor BRICKSTORM and a web shell called SLAYSTYLE.
Both BRICKSTORM and SLAYSTYLE have also been observed in the new Dell RecoverPoint attributed to UNC6201. However, the threat actor also deployed a new backdoor called GRIMBOLT.

“GRIMBOLT is a backdoor written in C# that is compiled using native ahead-of-time (AOT) compilation and packaged with UPX,” Mandiant researchers said. “It provides remote shell capability and uses the same command and control as BRICKSTORM.”
See also: Notepad++ fixes update mechanism used to distribute malware
There is evidence that UNC6201 has been exploiting CVE-2026-22769 since mid-2024 to deploy the SLAYSTYLE web shell. However, the replacement of BRICKSTORM with GRIMBOLT did not occur until September 2025. It is unclear whether this was the result of a planned iteration or a reaction to the BRICKSTORM disclosure by Mandiant.
New techniques
In addition to the payloads themselves, the research also uncovered new techniques. For example, the legitimate shell script convert_hosts.sh present on these devices has been modified to include the path to the backdoors to achieve persistence.
The SLAYSTYLE web shell, which is designed to receive commands over HTTP and execute them on the system, was used to create proxy rules via the Linux iptables utility . Specifically, incoming traffic on port 443 (HTTPS), containing a specific HEX string, was silently redirected to port 10443 for the next 5 minutes.
Another new technique was to create temporary network ports on existing virtual machines on VMware ESXi servers, to access other services within the environments.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Zimbra patches XSS, XXE & LDAP Injection vulnerabilities

Charles Carmakal, CTO at Mandiant, described the technique on LinkedIn as “deploying ghost NICs on virtual machines to evade defenders,” because it let researchers hunt for network activity from IP addresses that no longer existed and had never been documented.
Dell recommends deploying RecoverPoint for VMs within a trusted, access-controlled network behind appropriate firewalls and segregation, not on publicly accessible infrastructure. Meanwhile, Mandiant's blog post includes breach indicators and YARA detection rules for the new GRIMBOLT and SLAYSTYLE payloads.
