Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators VerdantBamboo: Just Another BRICKSTORM in the Firewall

320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759

TLP:CLEAR
Active

SHA-256 Hash

Description

Chinese threat actor VerdantBamboo compromised a victim organization and its Managed Services Provider over an 18-month period, deploying malware on network edge devices lacking EDR coverage. The initial breach involved an Egnyte Storage Sync system, where attackers exploited a sudo misconfiguration for privilege escalation and installed BRICKSTORM backdoor and AGENTPSD fallback implant. Investigation revealed the MSP's pfSense firewall was also compromised with a FreeBSD variant of BRICKSTORM. After remediation, VerdantBamboo regained access through stolen firewall credentials, enabling custom VPN access and deploying PLENET backdoor on a Synology NAS. The threat actor leveraged compromised systems as proxies to access Microsoft 365 environments while evading security controls. VerdantBamboo demonstrated operational discipline by targeting appliances without EDR capabilities and using sophisticated malware including PLENET, compiled with .NET Native AOT to hinder analysis.

Sightings (0)

No sightings recorded yet

Details

Name / Label
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:08
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.