Executive Summary
BRICKSTORM is a multi‑platform backdoor engineered for stealthy command‑and‑control operations across Windows, Linux, ESXi, and network devices. Its Go/Rust/.NET AOT implementations allow operators to deliver secondary payloads and exfiltrate data undetected, especially within high‑value targets such as F5 Big‑IP appliances.
Enhanced Description
BRICKSTORM is a sophisticated, cross‑platform backdoor that supports multiple code bases—including Go, Rust, and an ahead‑of‑time (AOT) compiled .NET variant—allowing it to blend seamlessly into Windows, Linux, ESXi, and network device environments such as F5 Big‑IP. First identified in April 2024, the malware orchestrates a full command and control (C2) loop: it receives instructions from remote servers, drops additional payloads for further compromise, and exfiltrates data back to adversary infrastructure over encrypted channels. Operators leverage BRICKSTORM to stage subsequent attacks by uploading or fetching malicious binaries on victim hosts. The backdoor’s lightweight footprint and native binary compilation help evade traditional signature‑based defenses, while its ability to run on network devices expands the attack surface for lateral movement and persistence. Threat actors linked to this tool include several China‑state‑nexus groups—UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE—highlighting a coordinated effort to target high‑value infrastructure. By combining hardened encryption, multi‑platform support, and the capability to embed additional malware, BRICKSTORM enables attackers to maintain long‑term footholds in complex enterprise environments while collecting strategic intelligence and exfiltrating critical data.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on multiple authoritative sources, including CISA advisories and vendor reports, providing high confidence in functionality and actor attribution. However, specific code samples, versioning details, and a complete mapping of all variants are not publicly documented, leaving gaps around the full attack‑lifecycle coverage for each platform.
BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of other malware, and the exfiltration of data.(Citation: CISA BRICKSTORM UNC5221 AR25-338A February 2026)(Citation: Picus Security BRICKSTORM UNC5221 October 2025)(Citation: Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025)(Citation: Google BRICKSTORM September 2025) BRICKSTORM has also been created from a .NET application using ahead-of-time (AOT) compilation to blend in within victim environments.(Citation: CISA BRICKSTORM UNC5221 AR25-338A February 2026) BRICKSTORM was first observed in April 2024.(Citation: Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024) BRICKSTORM has previously been leveraged by People's Republic of China (PRC) state-nexus actors identified as UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE.(Citation: Cloudflare 2026 Threat Report New Threat Actors March 2026)(Citation: CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025)(Citation: CISA BRICKSTORM UNC5221 AR25-338A February 2026)(Citation: Dragos SYLVANITE MuddyWater Electrum March 2026)(Citation: NVISO BRICKSTORM April 2025)(Citation: Google BRICKSTORM GRIMBOLT UNC5221 UNC6201 February 2026)(Citation: Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025)(Citation: Google BRICKSTORM September 2025)