Under the radar – Google warns new Brickstorm malware was stealing data from US firms for over a year

  • Google warns UNC5221 targeted US legal, tech, and SaaS firms with Brickstorm malware for over a year
  • Campaign aimed at espionage, intellectual property theft, and long-term infrastructure access
  • Mandiant urges TTP-based threat hunting and stronger authentication to counter future attacks

US organizations across the legal, technology, SaaS, and business process outsourcing sectors were targeted by a new malware variant named Brickstorm for over a year, leading to major data loss, experts have warned.

Google’s Threat Intelligence Group (GTIG) found the threat actors behind the campaign are UNC5221, a suspected China-nexus threat known for stealthy operations and long-term persistence.

This group first targeted zero-day vulnerabilities in Linux devices and BSD-based appliances, since these are often overlooked in asset inventories and excluded from central logging. As such, they make for an ideal foothold for the attackers.

Cyber-espionage

Once inside, UNC5221 used Brickstorm to move laterally, harvest credentials, and exfiltrate data with minimal telemetry. In some cases, the malware remained undetected for more than a year, since the average dwell time was said to be a mighty 393 days.

In many cases, they would pivot from fringe devices to VMware vCenter and ESXi hosts, using stolen credentials to deploy Brickstorm and escalate privileges.

To maintain persistence, they modified startup scripts and deployed webshells that allowed for remote command execution. They cloned sensitive virtual machines without even powering them on, and thus avoiding triggering security tools.

The campaign’s objectives appear to span geopolitical espionage, intellectual property theft, and access operations.

Since legal companies were targeted as well, the researchers suspected UNC5221 was interested in US national security, and trade topics, while targeting SaaS providers could have been used to pivot into downstream customer environments.

To counter Brickstorm, Mandiant recommends a threat-hunting approach based on tactics, techniques, and procedures (TTPs) rather than atomic indicators, which have proven unreliable due to the actor’s operational discipline.

The researchers urged businesses to update asset inventories, monitor appliance traffic, and enforce multi-factor authentication.

You might also like

Read more @ TechRadar

Latest posts

MGM+ series Robin Hood finally reveals Eleanor of Aquitaine, but you’ll never guess Connie Nielsen’s inspiration for the role

Warning: mild spoilers for Robin Hood episode 3 ahead.Connie Nielsen's Eleanor of Aquitaine is my favorite character in the new MGM+ version of Robin...

I tested the official Nintendo Switch 2 carry case, and it’s a slim and stylish option well worth considering

Nintendo Switch 2 Carrying Case & Screen Protector: reviewWant to take your beloved Nintendo Switch 2 on the road without the fear of damage...

Gigabyte Gaming A16 Pro review: this restricted RTX 5080 machine holds its own thanks to 5070 Ti pricing

Gigabyte Gaming A16 Pro: Two-minute reviewPowered by an RTX 5080 and featuring a large 16-inch, 165 Hz display, the A16 Pro delivers excellent gaming...

You need to listen to this compilation of ‘80s Spanish ambient and electronic music

Much of La Ola Interior (Spanish Ambient & Acid Exoticism 1983-1990) sounds shockingly contemporary for a collection of tracks recorded in the mid to...

Cleveland Guardians’ pitchers indicted for rigging online bets

Cleveland Guardians pitchers Emmanuel Clase and Luis Ortiz were indicted in Brooklyn on charges that they conspired to illegally rig bets on pitches thrown...

How to adjust the Liquid Glass effect in iOS 26.1

Apple's latest iterative update for iPhones brings a welcome change for those who aren't a fan of its Liquid Glass design overhaul. After user...

Blue Origin scrubs New Glenn’s second flight due to bad weather

Blue Origin has postponed the second flight of its New Glenn rocket, which was slated to send a pair of NASA spacecraft on the...

YouTube TV is giving subscribers a $20 credit as consolation for the Disney blackout

YouTube TV has notified subscribers that a $20 credit is heading their way in light of its ongoing standoff with Disney, which has resulted...

I might have just found the hands down best art app for gallery lovers

In December 2024, I wrote about my newfound love for the DailyArt app. Through images, short stories, and text descriptions, I was able to...

Got a spare $50,000? Cooling a single Nvidia Blackwell Ultra NVL72 rack costs as much as a Tesla Model Y – and it’s only...

Cooling costs surge as Nvidia pushes power limits across successive rack generationsCompute trays dominate expenses due to rising cold plate requirements and thermal densitySwitch...