Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Exploit BRICKSTORM to Infiltrate Networks

Chinese Hackers Exploit BRICKSTORM to Infiltrate Networks

Posted on June 5, 2026 By CWS

A Chinese state-affiliated hacking group, identified as VerdantBamboo, has been covertly infiltrating corporate networks for over a year. Utilizing a unique malware kit, they have managed to compromise firewalls, storage systems, and network appliances without setting off any alarms.

Uncovering VerdantBamboo’s Infiltration

VerdantBamboo, noted for its patience and technical precision, was brought to light when unusual network activity was detected on a Linux-based virtual machine within a client’s network. The device, an Egnyte Storage Sync appliance, was supposed to connect to Egnyte’s infrastructure but was instead communicating with a domain owned by the attackers, camouflaged behind Cloudflare IPs and utilizing Google’s public DNS server for encrypted query resolution.

Volexity, a threat intelligence and incident response company, identified the malware behind these activities as BRICKSTORM, a remote access trojan under continuous development. According to Volexity, VerdantBamboo, also known as WARP PANDA and UNC5221, had maintained access to the compromised network for at least 18 months before discovery.

Advanced Intrusion Techniques

The attack was more intricate than initially perceived. VerdantBamboo not only breached the victim’s systems but also infiltrated their Managed Services Provider (MSP). This gave the group access to sensitive credentials and internal infrastructure data, enabling them to bypass standard security controls and establish a foothold within the victim’s environment.

Even after being expelled, VerdantBamboo demonstrated resilience by re-entering the network. They used stolen administrative credentials to access the victim’s exposed firewall, established a VPN tunnel, and implanted a new backdoor on a Synology NAS device. This adaptability complicated recovery efforts significantly.

BRICKSTORM and Additional Threats

BRICKSTORM, VerdantBamboo’s primary malware, is designed to operate undetected in environments that lack traditional security monitoring. Built in Golang, its modular architecture allows for customization per target device. On Egnyte appliances, BRICKSTORM was manually executed, exploiting a misconfigured sudo rule to gain elevated privileges.

Volexity also discovered two previously undocumented malware families: PLENET, a cross-platform backdoor, and AGENTPSD, a lightweight Python reverse shell. These were likely deployed as fallback options in case BRICKSTORM’s operation was disrupted.

Preventive Measures and Future Outlook

Volexity tracked VerdantBamboo’s command-and-control servers using a Censys platform query, which led to the identification of servers with minimal services on port 443. Once the fingerprint was developed, all matching servers went offline, suggesting the hackers were alerted to the investigation.

To mitigate such threats, organizations must ensure edge appliances are not directly internet-accessible without MFA. Privileged accounts should be audited, and systems unable to run EDR agents should have compensating controls like network traffic monitoring and strict access policies to detect persistent compromises.

As the cyber landscape evolves, staying vigilant against advanced persistent threats like VerdantBamboo remains crucial. Continuous monitoring, proactive security measures, and incident response readiness are essential to safeguarding network integrity.

Cyber Security News Tags:APT, APT attack, BRICKSTORM, Chinese hackers, cyber attack, Cybersecurity, Firewalls, incident response, Malware, managed services, network breach, network security, threat intelligence, VerdantBamboo, Volexity

Post navigation

Previous Post: AI Threats and Cybersecurity Updates This Week
Next Post: New Cyber Threat OP-512 Hits Microsoft IIS Servers

Related Posts

Hackers Weaponize Fake Microsoft Teams Site to Deploy Odyssey macOS Stealer Hackers Weaponize Fake Microsoft Teams Site to Deploy Odyssey macOS Stealer Cyber Security News
WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch Cyber Security News
EvilTokens and AMOS: Major Phishing Threats of March 2026 EvilTokens and AMOS: Major Phishing Threats of March 2026 Cyber Security News
EtherRAT Malware Hides Using Ethereum Blockchain EtherRAT Malware Hides Using Ethereum Blockchain Cyber Security News
MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command Cyber Security News
Microsoft To Mandate MFA for Accounts Signing In to the Azure Portal Microsoft To Mandate MFA for Accounts Signing In to the Azure Portal Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
  • Chrome 149 Update Fixes Record 429 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
  • Chrome 149 Update Fixes Record 429 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark