Chinese APT Uses BRICKSTORM Malware for Espionage
Chinese APT VerdantBamboo Uses BRICKSTORM Malware for Long-Term Espionage A Chinese advanced persistent threat group tracked as VerdantBamboo is reportedly using BRICKSTORM malware to maintain stealthy, long-term access inside targeted environments. BRICKSTORM is not ordinary commodity malware. It is a sophisticated backdoor associated with espionage-focused operations, appliance compromise, stealthy persistence, encrypted command and control, and low-noise lateral movement. For enterprises, this campaign is especially concerning because the attackers appear focused on systems that often sit outside traditional endpoint visibility. These may include edge appliances, virtualization management platforms, Linux systems, BSD-based appliances, and other infrastructure where endpoint detection tools are limited or absent. When attackers compromise these systems, they can remain hidden for months while quietly collecting credentials, mapping the environment, and preparing selective data...