BRICKSTORM
MITRE ATT&CK: S9015 View on attack.mitre.org
Aliases: BRICKSTORM
- First seen
- 2024-04-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- esxi, linux, network-devices, windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-08-11 09:16:13
- Profile updated
- 2026-07-07 13:11:10
Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace
Context
BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of other malware, and the exfiltration of data. BRICKSTORM has also been created from a .NET application using ahead-of-time (AOT) compilation to blend in within victim environments. BRICKSTORM was first observed in April 2024. BRICKSTORM has previously been leveraged by People's Republic of China (PRC) state-nexus actors identified as UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to BRICKSTORM (S9015). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df.elf | 2026-08-11 | 2 |
Detection coverage
- 7 YARA rules
- 374 Sigma rules
Malware & tools used
- Obfuscated Files or Information (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Web Protocols (attack-pattern)
- Relocate Malware (attack-pattern)
- Process Discovery (attack-pattern)
- Path Interception by PATH Environment Variable (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Prevent Command History Logging (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Create or Modify System Process (attack-pattern)
- Protocol Tunneling (attack-pattern)
- File Deletion (attack-pattern)
- Standard Encoding (attack-pattern)
- Delay Execution (attack-pattern)
- Dynamic Resolution (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Web Service (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Internal Proxy (attack-pattern)
- Unix Shell (attack-pattern)
- DNS (attack-pattern)
- Service Stop (attack-pattern)
- Data from Local System (attack-pattern)
Detection rules
- VOLEXITY_Apt_Malware_Golang_Brickstorm_B (yara-rule)
- VOLEXITY_Apt_Malware_Golang_Brickstorm (yara-rule)
- VOLEXITY_Apt_Malware_Any_Brickstorm_Rust (yara-rule)
- SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_3 (yara-rule)
- SIGNATURE_BASE_MAL_G_Backdoor_BRICKSTORM_2 (yara-rule)
- SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_1 (yara-rule)
- SIGNATURE_BASE_MAL_G_APT_Backdoor_BRICKSTORM_2 (yara-rule)
Reports & references
- cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)
- CrowdStrike — Warp Panda Cloud Threats (report)
- cloud.google.com — Unc6201 Exploiting Dell Recoverpoint Zero Day (report)
- blog.cloudflare.com — 2026 Threat Report (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Brickstorm (report)
- CISA — Ar25 338A (report)
- cloud.google.com — Brickstorm Espionage Campaign (report)
- blog.nviso.eu — Nviso Brickstorm Report (report)
- cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)
- threatprotect.qualys.com — F5 Big Ip Source Code Leaked In State Linked Cyberattack Brickstorm Malware (report)
- hub.dragos.com — 2026 Yir Executivebriefing%20O G (report)
- MITRE ATT&CK — S9015 (report)
- picussecurity.com — Brickstorm Malware Unc5221 Targets Tech And Legal Sectors In The United States (report)
- resecurity.com — F5 Big Ip Source Code Leak Tied To State Linked Campaigns Using Brickstorm Backdoor (report)
External references
- mitre-attack — S9015
- Cloudflare 2026 Threat Report New Threat Actors March 2026
- CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025
- CISA BRICKSTORM UNC5221 AR25-338A February 2026
- Dragos SYLVANITE MuddyWater Electrum March 2026
- Picus Security BRICKSTORM UNC5221 October 2025
- Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024
- NVISO BRICKSTORM April 2025
- Google BRICKSTORM GRIMBOLT UNC5221 UNC6201 February 2026
- Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025
- Google BRICKSTORM September 2025
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy