Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators VerdantBamboo: Just Another BRICKSTORM in the Firewall

24a11a26a2586f4fba7bfe89df2e21a0809ad85069e442da98c37c4add369a0c

TLP:CLEAR
Active

SHA-256 Hash

Description

Chinese threat actor VerdantBamboo compromised a victim organization and its Managed Services Provider over an 18-month period, deploying malware on network edge devices lacking EDR coverage. The initial breach involved an Egnyte Storage Sync system, where attackers exploited a sudo misconfiguration for privilege escalation and installed BRICKSTORM backdoor and AGENTPSD fallback implant. Investigation revealed the MSP's pfSense firewall was also compromised with a FreeBSD variant of BRICKSTORM. After remediation, VerdantBamboo regained access through stolen firewall credentials, enabling custom VPN access and deploying PLENET backdoor on a Synology NAS. The threat actor leveraged compromised systems as proxies to access Microsoft 365 environments while evading security controls. VerdantBamboo demonstrated operational discipline by targeting appliances without EDR capabilities and using sophisticated malware including PLENET, compiled with .NET Native AOT to hinder analysis.

Sightings (0)

No sightings recorded yet

Details

Name / Label
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:08
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 24a11a26a2586f4fba7bfe89df2e21a0809ad85069e442da98c37c4add369a0c

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.