Drooid Logo
Back to story perspectives

Full Breakdown

Chinese Cyber Espionage Campaign: The BRICKSTORM Backdoor

9/25/2025, 6:30:59 AM

Overview of the BRICKSTORM Campaign

A sophisticated cyber espionage campaign attributed to a group known as UNC5221, suspected to be linked to the Chinese government, has targeted U.S. technology companies, legal firms, and Software-as-a-Service (SaaS) providers. This campaign utilizes a stealthy backdoor malware called BRICKSTORM, which allows the hackers to maintain persistent access to victim networks for an average of 393 days. The primary objective appears to be the theft of sensitive data, including intellectual property and information related to U.S. national security and international trade.

Targeted Sectors and Methods

The BRICKSTORM campaign has focused on sectors critical to national security, including legal services and technology. By infiltrating SaaS providers, the attackers aim to access downstream customer environments, creating a significant supply chain risk. The malware is designed to operate on network appliances that lack traditional endpoint detection and response (EDR) capabilities, such as firewalls and VMware systems, making detection challenging.

The attackers employ advanced techniques, including exploiting zero-day vulnerabilities in Ivanti Connect Secure devices to gain initial access. Once inside, they deploy BRICKSTORM to maintain access and utilize its SOCKS proxy feature to tunnel into sensitive applications. Notably, the malware can clone virtual machines without powering them on, further evading detection.

Official Statements & Responses

Charles Carmakal, Chief Technology Officer at Mandiant, emphasized the sophistication of the BRICKSTORM campaign, stating, "The access obtained by UNC5221 enables them to pivot to downstream customers of compromised SaaS providers or discover zero-day vulnerabilities in enterprise technologies." Google has released a free scanning tool to help organizations detect BRICKSTORM activity, highlighting the need for comprehensive security measures.

Criticism & Opposition

Despite the ongoing investigations, some experts have raised concerns about the effectiveness of current cybersecurity measures against such advanced threats. The FBI is actively investigating these breaches, but the scale and stealth of the attacks have led to fears that many organizations may remain unaware of their compromised status.

Conflicting Reports & Gaps

While Google and Mandiant have attributed the campaign to UNC5221, there is ongoing debate about the extent of collaboration between various Chinese hacking groups. The overlap with other groups, such as Silk Typhoon, complicates the attribution and understanding of the full scope of these cyber activities.

What's Next

The implications of the BRICKSTORM campaign are expected to resonate for years, as organizations continue to uncover evidence of past compromises. Experts predict that as more companies scan their systems, new victims will emerge, and additional vulnerabilities may be exploited. The campaign underscores the necessity for organizations to enhance their security protocols, particularly concerning network appliances and edge devices.

Verbatim Quotes

  • “The BRICKSTORM campaign represents a significant threat due to its sophistication, evasion of advanced enterprise security defenses, and focus on high-value targets,” — Charles Carmakal, CTO of Mandiant Consulting at Google Cloud.
  • “This is a very, very advanced adversary.” — Charles Carmakal, Mandiant Consulting.
  • “We believe that there are many organizations that are actively compromised that don’t know about it.” — Charles Carmakal, Mandiant Consulting.
  • “The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims,” — Google Threat Intelligence Group.

The BRICKSTORM campaign highlights the evolving landscape of cyber threats, particularly from state-sponsored actors, and the critical need for organizations to adapt their security strategies accordingly.