BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Hackers Target Linux With BRICKSTORM

Chinese espionage group deploys multiple backdoors in persistent cross-platform intrusion campaign.

  • The China-nexus cyber espionage group VerdantBamboo deployed a BSD variant of the BRICKSTORM backdoor against Linux systems.
  • The group compromised an Egnyte Storage Sync system in September 2025 by exploiting a local privilege escalation flaw, using it to access a victim’s Microsoft 365 environment.
  • Following remediation, the actor returned using stolen credentials, deploying new malware families PLENET and AGENTPSD to a Synology NAS device.
  • The attacks have been linked to hacking clusters known as Clay Typhoon, UNC5221, and Warp Panda.
  • The PLENET malware was previously used in attacks exploiting a Dell RecoverPoint zero-day vulnerability (CVE-2026-22769).

In a sophisticated and persistent campaign, the Chinese cyber espionage group VerdantBamboo has been deploying multiple malware families, including a BSD variant of the BRICKSTORM backdoor, to compromise Linux systems. According to a technical report from Volexity, the activity overlaps with clusters tracked as Clay Typhoon and UNC5221.

- Advertisement -

Volexity discovered the intrusion during a September 2025 incident response, finding the group had breached an Egnyte Storage Sync appliance. The threat actor exploited a privilege escalation flaw, later patched in version 13.13, to deploy BRICKSTORM. Researchers stated, “The appliance had periodically been accessed by VerdantBamboo via IP addresses assigned through the victim organization’s web SSL VPN.”

Consequently, the malware’s proxying capabilities were used with stolen credentials to infiltrate the victim’s Microsoft 365 environment. This tactic aimed to blend with legitimate traffic and bypass security policies, with the initial compromise dating back at least 18 months. Following initial remediation, the actors staged a return using stolen admin credentials.

Meanwhile, the group breached the victim’s firewall to configure VPN access and deployed additional payloads to a Synology NAS. The newly deployed malware included PLENET, a cross-platform .NET Core backdoor, and AGENTPSD, a Python-based reverse shell. Further investigation revealed the group had also compromised the victim’s Managed Services Provider, infecting its pfSense firewall with the BSD BRICKSTORM variant.

Notably, PLENET was used in earlier attacks exploiting a critical Dell RecoverPoint vulnerability (CVE-2026-22769). Volexity assessed VerdantBamboo as highly sophisticated, leveraging living-off-the-land techniques on systems without EDR software. The group demonstrates strong operational security, using limited infrastructure per victim and customizing implants for each device.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Wall Street Eyes Community Backlash as Data Center Credit Risk

Wall Street lenders are factoring community opposition into credit-risk assessments for data center projects.At...

AI’s Moat Will Emerge Through Access and Licensing

Frontier AI models currently lack a defensive moat, as rivals can copy and paste...

Bitcoin dips below $64,500 amid Iran-Hormuz uncertainty, yen weakness

Bitcoin fell below $64,500 as US-Iran tensions cast doubt on reopening the Strait of...

North Korean hackers deploy offline AI for espionage

North Korea's Kimsuky hacking group is now running AI models offline on its own...

Roth Capital Sets $325 Amazon Stock Target

Amazon shares opened Monday at $274 after a 21.5% year-to-date surge.Roth Capital Partners issued...

Must Read

How to Check The Rarity of An NFT

Whenever you invest in an NFT collection, you might have noticed that some NFTs are more expensive than others. NFT collections are often made...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading