Skip to main content
Cyber Week Sale - Get 40% off Vantage
Published loading...Updated

PRC Spies Brickstromed Their Way Into Critical US Networks

PRC-backed cyber groups infected over 30 US organizations using Brickstorm malware to steal data and maintain access in critical infrastructure, cybersecurity firms report.

  • On Thursday, government cybersecurity teams warned that PRC-backed actors infected at least eight government services and IT organizations with Brickstorm malware, maintaining long-term access and stealing data.
  • CrowdStrike attributed the backdoor to Warp Panda active since at least 2022, while Mandiant has responded since March and CISA's Nick Andersen called Brickstorm "a terribly sophisticated piece of malware".
  • Using Brickstorm, operators tunneled traffic to replay user sessions for Microsoft 365 access and pivoted to VMware vCenter and ESXi environments, deploying Junction and GuestConduit implants.
  • Following vendor reports, Google Threat Intelligence Group urged running Mandiant's open-source scanner on GitHub, while Broadcom officials advised customers to patch VMware software and secure vSphere environments.
  • On numerous occasions, Palo Alto Networks' Unit 42 observed UNC5221 planting custom backdoors, hindering detection and enabling long-term access, as Renals stated.
Insights by Ground AI

9 Articles

On 4 December 2025, the US cybersecurity agency CISA published an alarming report on the malicious software BRICKSTORM. This back door, attributed to Chinese state-sponsored cyber actors, would have allowed for infiltration and continued access within several government organisations.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

IT Security News - cybersecurity, infosecurity news broke the news in on Thursday, December 4, 2025.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal