ATT&CKSoftwareBRICKSTORM

BRICKSTORM

S9015

Malware.View on attack.mitre.org

About this malware

BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of other malware, and the exfiltration of data. BRICKSTORM has also been created from a .NET application using ahead-of-time (AOT) compilation to blend in within victim environments. BRICKSTORM was first observed in April 2024. BRICKSTORM has previously been leveraged by People's Republic of China (PRC) state-nexus actors identified as UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1005
Data from Local System

BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file.

T1027
Obfuscated Files or Information

BRICKSTORM has utilized Go libraries to include Garble to obfuscate code.

T1027.013
Encrypted/Encoded File

BRICKSTORM has utilized XOR cipher encryption to hide key strings within their code, to include IPv4 addresses of public DNS-over-HTTPS (DOH) servers.

T1036.005
Match Legitimate Resource Name or Location

BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`.

T1041
Exfiltration Over C2 Channel

BRICKSTORM has uploaded files from the victim system to C2 servers.

T1057
Process Discovery

BRICKSTORM has the ability to check if it is running as an active child process through the detection of a specific environment variable.

T1059.004
Unix Shell

BRICKSTORM has executed shell commands using `/bin/sh`.

T1070.004
File Deletion

BRICKSTORM has the ability to delete files and directories. BRICKSTORM also has deleted installer files after execution to reduce detection.

T1070.010
Relocate Malware

BRICKSTORM has copied itself to the `usr/sbin/` folder.

T1071.001
Web Protocols

BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers. BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls.

T1071.004
DNS

BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection.

T1083
File and Directory Discovery

BRICKSTORM has identified specific files and directories within targeted hosts and systems for modification, execution, collection and exfiltration.

T1090.001
Internal Proxy

BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic.

T1102
Web Service

BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications.

T1105
Ingress Tool Transfer

BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.

View all 25 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References10

  1. CISA BRICKSTORM UNC5221 AR25-338A February 2026 Open source
    DHS/CISA. (2026, February 11). AR25-338A: BRICKSTORM Backdoor. Retrieved April 16, 2026.
  2. Cloudflare 2026 Threat Report New Threat Actors March 2026 Open source
    Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.
  3. CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025 Open source
    CrowdStrike. (2025, December 4). Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary. Retrieved April 16, 2026.
  4. Dragos SYLVANITE MuddyWater Electrum March 2026 Open source
    Dragos. (2026, March 24). Dragos 2026 OT Cybersecurity Report: Year in Review, O&G and Petrochemicals Focus. Retrieved April 17, 2026.
  5. Google BRICKSTORM GRIMBOLT UNC5221 UNC6201 February 2026 Open source
    Peter Ukhanov, Daniel Sislo, Nick Harbour, John Scarbrough, Fernando Tomlinson Jr., Rich Reece. (2026, February 17). From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day. Retrieved April 16, 2026.
  6. Google BRICKSTORM September 2025 Open source
    Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen. (2025, September 24). Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors. Retrieved April 16, 2026.
  7. Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024 Open source
    Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies. Retrieved April 16, 2026.
  8. NVISO BRICKSTORM April 2025 Open source
    NVISO Incident Response. (2025, April 1). BRICKSTORM Backdoor Analysis: A Persistent Espionage Threat to European Industries. Retrieved April 16, 2026.
  9. Picus Security BRICKSTORM UNC5221 October 2025 Open source
    Huseyin Can Yuceel. (2025, October 1). BRICKSTORM Malware: UNC5221 Targets Tech and Legal Sectors in the United States. Retrieved April 16, 2026.
  10. Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 Open source
    Resecurity Threat Intelligence & Incident Analysis. (2025, October 22). F5 BIG-IP Source Code Leak Tied to State-Linked Campaigns Using BRICKSTORM Backdoor. Retrieved April 16, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.