BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Hackers Target Linux With BRICKSTORM

Chinese espionage group deploys multiple backdoors in persistent cross-platform intrusion campaign.

  • The China-nexus cyber espionage group VerdantBamboo deployed a BSD variant of the BRICKSTORM backdoor against Linux systems.
  • The group compromised an Egnyte Storage Sync system in September 2025 by exploiting a local privilege escalation flaw, using it to access a victim’s Microsoft 365 environment.
  • Following remediation, the actor returned using stolen credentials, deploying new malware families PLENET and AGENTPSD to a Synology NAS device.
  • The attacks have been linked to hacking clusters known as Clay Typhoon, UNC5221, and Warp Panda.
  • The PLENET malware was previously used in attacks exploiting a Dell RecoverPoint zero-day vulnerability (CVE-2026-22769).

In a sophisticated and persistent campaign, the Chinese cyber espionage group VerdantBamboo has been deploying multiple malware families, including a BSD variant of the BRICKSTORM backdoor, to compromise Linux systems. According to a technical report from Volexity, the activity overlaps with clusters tracked as Clay Typhoon and UNC5221.

- Advertisement -

Volexity discovered the intrusion during a September 2025 incident response, finding the group had breached an Egnyte Storage Sync appliance. The threat actor exploited a privilege escalation flaw, later patched in version 13.13, to deploy BRICKSTORM. Researchers stated, “The appliance had periodically been accessed by VerdantBamboo via IP addresses assigned through the victim organization’s web SSL VPN.”

Consequently, the malware’s proxying capabilities were used with stolen credentials to infiltrate the victim’s Microsoft 365 environment. This tactic aimed to blend with legitimate traffic and bypass security policies, with the initial compromise dating back at least 18 months. Following initial remediation, the actors staged a return using stolen admin credentials.

Meanwhile, the group breached the victim’s firewall to configure VPN access and deployed additional payloads to a Synology NAS. The newly deployed malware included PLENET, a cross-platform .NET Core backdoor, and AGENTPSD, a Python-based reverse shell. Further investigation revealed the group had also compromised the victim’s Managed Services Provider, infecting its pfSense firewall with the BSD BRICKSTORM variant.

Notably, PLENET was used in earlier attacks exploiting a critical Dell RecoverPoint vulnerability (CVE-2026-22769). Volexity assessed VerdantBamboo as highly sophisticated, leveraging living-off-the-land techniques on systems without EDR software. The group demonstrates strong operational security, using limited infrastructure per victim and customizing implants for each device.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

CFTC short-staffed for prediction market oversight, hearing told

A House subcommittee examined how the CFTC can oversee prediction market platforms amid a...

Apple fixes Hide My Email flaw that leaked real addresses for over a year

Apple fixed a flaw in its Hide My Email service on July 3, 2026,...

White House pushes Dems to accept Trump’s crypto ethics deal

The White House is urging Senate Democrats to accept President Trump's ethics deal to...

Telegram to roll out native Gram wallet for 1B users

Telegram founder Pavel Durov announced a native non-custodial Gram wallet rolling out to all...

Augustus raises $180M for Global Dollar Bank at $1B valuation

Augustus raised $180 million in Series B funding at a $1 billion valuation, led...

Must Read

What Are Sniper Bots Used in Defi Trading?

You've heard about DeFi, but what about sniper bots? These high-speed trading tools are shaking up the crypto scene.But don't fret, you're not...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading