BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Hackers Target Linux With BRICKSTORM

Chinese espionage group deploys multiple backdoors in persistent cross-platform intrusion campaign.

  • The China-nexus cyber espionage group VerdantBamboo deployed a BSD variant of the BRICKSTORM backdoor against Linux systems.
  • The group compromised an Egnyte Storage Sync system in September 2025 by exploiting a local privilege escalation flaw, using it to access a victim’s Microsoft 365 environment.
  • Following remediation, the actor returned using stolen credentials, deploying new malware families PLENET and AGENTPSD to a Synology NAS device.
  • The attacks have been linked to hacking clusters known as Clay Typhoon, UNC5221, and Warp Panda.
  • The PLENET malware was previously used in attacks exploiting a Dell RecoverPoint zero-day vulnerability (CVE-2026-22769).

In a sophisticated and persistent campaign, the Chinese cyber espionage group VerdantBamboo has been deploying multiple malware families, including a BSD variant of the BRICKSTORM backdoor, to compromise Linux systems. According to a technical report from Volexity, the activity overlaps with clusters tracked as Clay Typhoon and UNC5221.

- Advertisement -

Volexity discovered the intrusion during a September 2025 incident response, finding the group had breached an Egnyte Storage Sync appliance. The threat actor exploited a privilege escalation flaw, later patched in version 13.13, to deploy BRICKSTORM. Researchers stated, “The appliance had periodically been accessed by VerdantBamboo via IP addresses assigned through the victim organization’s web SSL VPN.”

Consequently, the malware’s proxying capabilities were used with stolen credentials to infiltrate the victim’s Microsoft 365 environment. This tactic aimed to blend with legitimate traffic and bypass security policies, with the initial compromise dating back at least 18 months. Following initial remediation, the actors staged a return using stolen admin credentials.

Meanwhile, the group breached the victim’s firewall to configure VPN access and deployed additional payloads to a Synology NAS. The newly deployed malware included PLENET, a cross-platform .NET Core backdoor, and AGENTPSD, a Python-based reverse shell. Further investigation revealed the group had also compromised the victim’s Managed Services Provider, infecting its pfSense firewall with the BSD BRICKSTORM variant.

Notably, PLENET was used in earlier attacks exploiting a critical Dell RecoverPoint vulnerability (CVE-2026-22769). Volexity assessed VerdantBamboo as highly sophisticated, leveraging living-off-the-land techniques on systems without EDR software. The group demonstrates strong operational security, using limited infrastructure per victim and customizing implants for each device.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Chinese man jailed for Bitcoin theft after memorizing wallet phrase

A Chinese court sentenced a man to nearly 11 years in prison for stealing...

Hayes Sells Worldcoin Days After Firm’s AI Bet

Arthur Hayes sold his Worldcoin (WLD) holdings days after his firm's research note touted...

Trump Iran-Israel Remarks Fuel Bitcoin Market Moves

Bitcoin briefly reclaimed $64,000 this week after a recovery from lows near $59,000 but...

Bitcoin Targets $92,630 If Key Support Holds

Bitcoin rebounded 6.5% to near $62,950 on Sunday, holding above the critical $60,000 support.Analysts...

Bitcoin Braced for Deeper Purge as Losses Lag 2022 Peak

Bitcoin’s 2026 realized losses of $174 billion have not yet surpassed the 2022 record...

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading