BRICKSTORM

MITRE ATT&CK: S9015 View on attack.mitre.org

Aliases: BRICKSTORM

First seen
2024-04-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
esxi, linux, network-devices, windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-08-11 09:16:13
Profile updated
2026-07-07 13:11:10

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Context

BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of other malware, and the exfiltration of data. BRICKSTORM has also been created from a .NET application using ahead-of-time (AOT) compilation to blend in within victim environments. BRICKSTORM was first observed in April 2024. BRICKSTORM has previously been leveraged by People's Republic of China (PRC) state-nexus actors identified as UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to BRICKSTORM (S9015). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df.elf 2026-08-11 2

Detection coverage

  • 7 YARA rules
  • 374 Sigma rules

Malware & tools used

  • Obfuscated Files or Information (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Web Protocols (attack-pattern)
  • Relocate Malware (attack-pattern)
  • Process Discovery (attack-pattern)
  • Path Interception by PATH Environment Variable (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Prevent Command History Logging (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Create or Modify System Process (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • File Deletion (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Delay Execution (attack-pattern)
  • Dynamic Resolution (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Web Service (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Internal Proxy (attack-pattern)
  • Unix Shell (attack-pattern)
  • DNS (attack-pattern)
  • Service Stop (attack-pattern)
  • Data from Local System (attack-pattern)

Detection rules

  • VOLEXITY_Apt_Malware_Golang_Brickstorm_B (yara-rule)
  • VOLEXITY_Apt_Malware_Golang_Brickstorm (yara-rule)
  • VOLEXITY_Apt_Malware_Any_Brickstorm_Rust (yara-rule)
  • SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_3 (yara-rule)
  • SIGNATURE_BASE_MAL_G_Backdoor_BRICKSTORM_2 (yara-rule)
  • SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_1 (yara-rule)
  • SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_2 (yara-rule)

Reports & references

  • cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)
  • CrowdStrike — Warp Panda Cloud Threats (report)
  • cloud.google.com — Unc6201 Exploiting Dell Recoverpoint Zero Day (report)
  • blog.cloudflare.com — 2026 Threat Report (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Brickstorm (report)
  • CISA — Ar25 338A (report)
  • cloud.google.com — Brickstorm Espionage Campaign (report)
  • blog.nviso.eu — Nviso Brickstorm Report (report)
  • cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)
  • threatprotect.qualys.com — F5 Big Ip Source Code Leaked In State Linked Cyberattack Brickstorm Malware (report)
  • hub.dragos.com — 2026 Yir Executivebriefing%20O G (report)
  • MITRE ATT&CK — S9015 (report)
  • picussecurity.com — Brickstorm Malware Unc5221 Targets Tech And Legal Sectors In The United States (report)
  • resecurity.com — F5 Big Ip Source Code Leak Tied To State Linked Campaigns Using Brickstorm Backdoor (report)

External references