HomeLatest NewsCyber SecurityChinese hackers use BrickStorm malware to dwell in networks for over a year, researchers say

Chinese hackers use BrickStorm malware to dwell in networks for over a year, researchers say

Cybersecurity researchers link BrickStorm campaign to UNC5221, reporting average 393-day network dwell time and theft of source code for identifying zero-day vulnerabilities

Preferred Source of Google

New Delhi — Researchers from Google’s Threat Intelligence Group and Mandiant have identified a prolonged Chinese cyberespionage campaign in which hackers reportedly remained inside compromised networks for an average of 393 days.

The attackers, linked to a group tracked as UNC5221, used a stealthy backdoor malware known as BrickStorm to collect sensitive information, according to a joint analysis released on Thursday.

The campaign, monitored by Mandiant since March 2025, targeted industries including legal services, software-as-a-service, technology and business process outsourcing.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Future-Ready Defence
Future-Ready Defence
A Leadership Dialogue on sovereign, trusted data infrastructure, AI readiness and mission resilience for Defence Forces.
Register Now →

Investigators said the prolonged dwell time made it difficult to determine how the attackers initially accessed networks, though in at least one case the compromise may have involved a zero-day vulnerability in an Ivanti product.

BrickStorm has been deployed on various appliances, including – and BSD-based devices, many of which do not support conventional endpoint detection tools.

Mandiant noted that UNC5221 frequently targeted VMware vCenter and ESXi servers, often moving laterally from the initially infected appliances using valid credentials likely harvested by the malware.

Advertisement

“The actor moved laterally to a vCenter server in the environment using valid credentials, which were likely captured by the malware running on the network appliances,” Mandiant said in its report.

The researchers said the campaign went beyond traditional espionage, with hackers exploiting access to downstream customers of compromised SaaS providers.

According to Charles Carmakal, at Mandiant Consulting, Google Cloud, the attackers were using stolen proprietary source code and intellectual to identify flaws and zero-day vulnerabilities in enterprise technology products.

Advertisement

“As part of this intrusion campaign, the threat actors are stealing proprietary source code and other intellectual property related to enterprise technologies that many other companies use,” Carmakal said.

“We believe the threat actors are analysing the stolen source code to find flaws and zero-day vulnerabilities to exploit in enterprise technology products.”

The researchers emphasised that the group’s activity could have wider implications for organisations relying on the affected enterprise technologies. By discovering and weaponising zero-day vulnerabilities, the attackers could potentially target additional downstream companies.

Mandiant and Google’s Threat Intelligence Group said they continue to track the activity and monitor affected sectors, noting that a Windows variant of the BrickStorm malware has been reported but not observed in their investigations.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
Advertisement
- Advertisement -
- Advertisement -

AI is speeding up existing cyberattacks, not creating ‘magic AI malware’, says Thoughtworks’ Lilly Ryan

Thoughtworks Principal Cybersecurity Engineer Lilly Ryan says that AI is amplifying existing cyberattacks rather than creating entirely new threats, forcing enterprises to rethink whether their security operations can respond at the speed of increasingly automated attacks.

RELATED ARTICLES