Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware BRICKSTORM

BRICKSTORM

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

BRICKSTORM is a multi‑platform backdoor engineered for stealthy command‑and‑control operations across Windows, Linux, ESXi, and network devices. Its Go/Rust/.NET AOT implementations allow operators to deliver secondary payloads and exfiltrate data undetected, especially within high‑value targets such as F5 Big‑IP appliances.

Enhanced Description

BRICKSTORM is a sophisticated, cross‑platform backdoor that supports multiple code bases—including Go, Rust, and an ahead‑of‑time (AOT) compiled .NET variant—allowing it to blend seamlessly into Windows, Linux, ESXi, and network device environments such as F5 Big‑IP. First identified in April 2024, the malware orchestrates a full command and control (C2) loop: it receives instructions from remote servers, drops additional payloads for further compromise, and exfiltrates data back to adversary infrastructure over encrypted channels. Operators leverage BRICKSTORM to stage subsequent attacks by uploading or fetching malicious binaries on victim hosts. The backdoor’s lightweight footprint and native binary compilation help evade traditional signature‑based defenses, while its ability to run on network devices expands the attack surface for lateral movement and persistence. Threat actors linked to this tool include several China‑state‑nexus groups—UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE—highlighting a coordinated effort to target high‑value infrastructure. By combining hardened encryption, multi‑platform support, and the capability to embed additional malware, BRICKSTORM enables attackers to maintain long‑term footholds in complex enterprise environments while collecting strategic intelligence and exfiltrating critical data.

Key Capabilities

  • Cross‑platform deployment (Windows, Linux, VMware ESXi, network gear)
  • Command & control via encrypted channels
  • Ingress transfer of additional malware payloads
  • Data exfiltration using C2 tunnels
  • Stealth through ahead‑of‑time compiled .NET binaries
  • Persistence on system and network devices
  • Enables lateral movement between hosts
  • Targets critical infrastructure (e.g., F5 Big‑IP) for high‑impact operations

ATT&CK Techniques

T1071.001 – Application Layer Protocol (Web)
T1048 — Exfiltration Over Alternative Protocol
T1105 — Remote File Copy
T1059.003 – PowerShell
T1120 — Multi‑Stage Obfuscation
T1060 — New Service
T1076 — Remote Services

Recommended Actions

  • Block outbound connections from known BRICKSTORM domains and IP ranges at the perimeter firewall.
  • Implement host IDS/EDR with heuristics for unknown Go/Rust binaries and AOT .NET executables that establish remote sockets.
  • Monitor VMware‑ESXi management interfaces for abnormal C2 traffic or unexpected process creation.
  • Enforce strong network segmentation to isolate critical devices from potential compromise vectors.
  • Apply timely patches for Cisco, F5, and other network device vendors; disable unused services such as SSH on non‑production devices.
  • Enable host‑based logging of PowerShell/command‑line activity and review for suspicious remote file copy commands.
  • Conduct regular threat hunting for backdoor persistence mechanisms like scheduled jobs or auto‑start registry keys.

Suggested Tags

BRICKSTORM
C2
Backdoor
Go
Rust
AOT.NET
State‑sponsored attack
PRC–based actor
F5 Big‑IP
VMware ESXi

Confidence Assessment

The analysis is based on multiple authoritative sources, including CISA advisories and vendor reports, providing high confidence in functionality and actor attribution. However, specific code samples, versioning details, and a complete mapping of all variants are not publicly documented, leaving gaps around the full attack‑lifecycle coverage for each platform.

Description

BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of other malware, and the exfiltration of data.(Citation: CISA BRICKSTORM UNC5221 AR25-338A February 2026)(Citation: Picus Security BRICKSTORM UNC5221 October 2025)(Citation: Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025)(Citation: Google BRICKSTORM September 2025) BRICKSTORM has also been created from a .NET application using ahead-of-time (AOT) compilation to blend in within victim environments.(Citation: CISA BRICKSTORM UNC5221 AR25-338A February 2026) BRICKSTORM was first observed in April 2024.(Citation: Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024) BRICKSTORM has previously been leveraged by People's Republic of China (PRC) state-nexus actors identified as UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE.(Citation: Cloudflare 2026 Threat Report New Threat Actors March 2026)(Citation: CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025)(Citation: CISA BRICKSTORM UNC5221 AR25-338A February 2026)(Citation: Dragos SYLVANITE MuddyWater Electrum March 2026)(Citation: NVISO BRICKSTORM April 2025)(Citation: Google BRICKSTORM GRIMBOLT UNC5221 UNC6201 February 2026)(Citation: Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025)(Citation: Google BRICKSTORM September 2025)

Details

Type
Malware
Platforms
Esxi
Linux
Network devices
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.