CISA, NSA, and Canadian Cyber Centre update Brickstorm analysis with new Rust-based variants - Industrial Cyber

CISA, NSA, and Canadian Cyber Centre announce update of the Brickstorm analysis with new Rust-based variants.

Industrial Cyber
Joint malware analysis report on Brickstorm backdoor - Canadian Centre for Cyber Security

This joint report warns that People’s Republic of China (PRC) state-sponsored threat actors are using Brickstorm malware for long-term persistence on victims’ systems.

Canadian Centre for Cyber Security
„Brickstorm“-Hintertür in VMware vSphere: Warnung vor Angriff aus China

Die CISA und die NSA warnen vor einem hochentwickelten Angriff auf Technik von VMware, mit dem sich Akteure aus China einen dauerhaften Zugang sichern könnten.

heise online

BRICKSTORM Backdoor

"The Cybersecurity and Infrastructure Security Agency (CISA) analyzed eight BRICKSTORM samples obtained from victim organizations. BRICKSTORM is a custom Executable and Linkable Format (ELF) Go-based backdoor. "

MISP standard and STIX files available at the following location:

🔗 https://cti-transmute.org/convert/detail/30

@misp
@cisacyber

#backdoor #cti #brickstorm #malware #threatintel #threatintelligence #cybersecurity

Cti-TRANSMUTE

📢 CISA/NSA et le Cyber Centre analysent BRICKSTORM, une backdoor Go ciblant VMware vSphere
📝 Selon un rapport TLP:CLEAR publié par la Cybersecurity and Infrastructure Security Agency (CISA), la National Security Agency (NSA...
📖 cyberveille : https://cyberveille.ch/posts/2025-12-05-cisa-nsa-et-le-cyber-centre-analysent-brickstorm-une-backdoor-go-ciblant-vmware-vsphere/
🌐 source : https://www.cisa.gov/news-events/analysis-reports/ar25-338a
#APT_chinois #BRICKSTORM #Cyberveille
CISA/NSA et le Cyber Centre analysent BRICKSTORM, une backdoor Go ciblant VMware vSphere

Selon un rapport TLP:CLEAR publié par la Cybersecurity and Infrastructure Security Agency (CISA), la National Security Agency (NSA) et le Centre canadien pour la cybersécurité, des acteurs étatiques de la RPC utilisent le malware BRICKSTORM pour maintenir une persistence de longue durée dans des environnements VMware vSphere (vCenter/ESXi) et aussi des environnements Windows. L’analyse couvre 8 échantillons et inclut des IOCs, des règles YARA et Sigma, ainsi que des recommandations de détection et d’atténuation.

CyberVeille

Chinese State Hackers are using new #BRICKSTORM malware against VMware systems according to a joint alert from US and Canadian agencies.

Read: https://hackread.com/chinese-state-hackers-brickstorm-vmware-systems/

#Cybersecurity #China #CISA #NSA #Malware #VMware

Chinese State Hackers Use New BRICKSTORM Malware Against VMware Systems

Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

📰 CISA Exposes 'BRICKSTORM' Backdoor Used by Chinese State Actors to Infiltrate US Government

📢 CISA, NSA & Canada warn of 'BRICKSTORM' malware used by PRC state actors against govt & IT sectors. The sophisticated backdoor targets VMware & Windows, using DoH for stealth C2 comms. 🛡️ #ThreatIntel #CyberSecurity #BRICKSTORM #China

🔗 https://cyber.netsecops.io/articles/cisa-warns-of-brickstorm-malware-used-by-chinese-hackers-against-us-government/?utm_source=mastodon&u…

CISA Exposes 'BRICKSTORM' Backdoor Used by Chinese State Actors to Infiltrate US Government

CISA, NSA, and the Canadian Cyber Centre have issued a joint alert on BRICKSTORM, a stealthy backdoor used by Chinese state-sponsored actors to target government and IT sectors. Learn the TTPs and mitigations.

CyberNetSec.io
CISA warns of Chinese "BrickStorm" malware attacks on VMware servers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned network defenders of Chinese hackers backdooring VMware vSphere servers with Brickstorm malware.

BleepingComputer