BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Hackers Target Linux With BRICKSTORM

Chinese espionage group deploys multiple backdoors in persistent cross-platform intrusion campaign.

  • The China-nexus cyber espionage group VerdantBamboo deployed a BSD variant of the BRICKSTORM backdoor against Linux systems.
  • The group compromised an Egnyte Storage Sync system in September 2025 by exploiting a local privilege escalation flaw, using it to access a victim’s Microsoft 365 environment.
  • Following remediation, the actor returned using stolen credentials, deploying new malware families PLENET and AGENTPSD to a Synology NAS device.
  • The attacks have been linked to hacking clusters known as Clay Typhoon, UNC5221, and Warp Panda.
  • The PLENET malware was previously used in attacks exploiting a Dell RecoverPoint zero-day vulnerability (CVE-2026-22769).

In a sophisticated and persistent campaign, the Chinese cyber espionage group VerdantBamboo has been deploying multiple malware families, including a BSD variant of the BRICKSTORM backdoor, to compromise Linux systems. According to a technical report from Volexity, the activity overlaps with clusters tracked as Clay Typhoon and UNC5221.

- Advertisement -

Volexity discovered the intrusion during a September 2025 incident response, finding the group had breached an Egnyte Storage Sync appliance. The threat actor exploited a privilege escalation flaw, later patched in version 13.13, to deploy BRICKSTORM. Researchers stated, “The appliance had periodically been accessed by VerdantBamboo via IP addresses assigned through the victim organization’s web SSL VPN.”

Consequently, the malware’s proxying capabilities were used with stolen credentials to infiltrate the victim’s Microsoft 365 environment. This tactic aimed to blend with legitimate traffic and bypass security policies, with the initial compromise dating back at least 18 months. Following initial remediation, the actors staged a return using stolen admin credentials.

Meanwhile, the group breached the victim’s firewall to configure VPN access and deployed additional payloads to a Synology NAS. The newly deployed malware included PLENET, a cross-platform .NET Core backdoor, and AGENTPSD, a Python-based reverse shell. Further investigation revealed the group had also compromised the victim’s Managed Services Provider, infecting its pfSense firewall with the BSD BRICKSTORM variant.

Notably, PLENET was used in earlier attacks exploiting a critical Dell RecoverPoint vulnerability (CVE-2026-22769). Volexity assessed VerdantBamboo as highly sophisticated, leveraging living-off-the-land techniques on systems without EDR software. The group demonstrates strong operational security, using limited infrastructure per victim and customizing implants for each device.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trueo leaves Base for Ethereum, cites oracle plans

Prediction market platform Trueo plans to migrate from the Base Network to Ethereum mainnet.The...

North Korea’s Contagious Interview hack steals $10.7M in crypto

North Korean threat actors compromised 30,000 devices across 100+ countries and stole from over...

X Sues Bot Network for $278K Creator Revenue Theft

X sued Vivek Kumar Sen and Zamyang Sherpa in London's High Court on September...

Tesla, Sunrun home batteries sent record 580 MW to CA grid

More than 140,000 household batteries discharged a record 580 megawatts into California's grid on...

Circle Launches Bitcoin-Backed Borrowing for Institutions Via USDC

Circle launched a Bitcoin-backed borrowing service for institutional clients, allowing eligible Circle Mint customers...

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading