A sophisticated Chinese cyber espionage group has been targeting American companies across multiple sectors using an advanced backdoor called BRICKSTORM, according to a new report from Mandiant and Google Threat Intelligence Group.
## Who’s Being Targeted
The attacks have focused on four key sectors in the United States:
– Legal services firms
– Software-as-a-Service (SaaS) providers
– Business Process Outsourcers (BPOs)
– Technology companies
The threat group, identified as UNC5221, has maintained persistent access to victim organizations for over a year on average—with some intrusions lasting up to 393 days undetected.
## Strategic Objectives
The hackers have clear strategic goals depending on their targets:
**SaaS Providers**: Gaining access to downstream customer environments and the sensitive data these providers host on behalf of their clients.
**Legal and Technology Sectors**: Gathering intelligence related to national security, international trade, and stealing intellectual property to develop zero-day exploits.
## The BRICKSTORM Backdoor
BRICKSTORM is a sophisticated Go-based backdoor first documented in connection with zero-day vulnerabilities in Ivanti Connect Secure devices. The malware has been active since at least November 2022 and includes powerful capabilities:
– Functions as a web server
– Performs file system manipulation
– Executes shell commands
– Acts as a SOCKS relay for network tunneling
– Communicates with command-and-control servers using WebSockets
## Advanced Evasion Techniques
What makes this campaign particularly dangerous is its stealth capabilities:
– **Minimal Detection**: The attackers deploy backdoors on network appliances that don’t support traditional endpoint detection tools
– **Memory-Only Operations**: Using custom tools that operate entirely in memory, avoiding file system traces
– **Long-Term Persistence**: Modifying system startup files to ensure backdoors survive reboots
– **Credential Harvesting**: Deploying malicious Java filters to capture administrator credentials
## Attack Methods
The hackers employ several sophisticated techniques:
1. **Initial Access**: Exploiting vulnerabilities in edge devices like Ivanti Connect Secure
2. **Lateral Movement**: Using stolen credentials to access VMware infrastructure
3. **Data Theft**: Targeting emails of key personnel including developers and system administrators
4. **Persistence**: Installing web shells and modifying system files for long-term access
## Industry Response
Google has developed a detection tool to help organizations identify BRICKSTORM infections on Linux and BSD-based systems. However, the company warns that the tool may not catch all variants of the malware.
“The BRICKSTORM campaign represents a significant threat due to its sophistication, evasion of advanced enterprise security defenses, and focus on high-value targets,” said Charles Carmakal, CTO of Mandiant Consulting at Google Cloud.
## Recommendations
Security experts recommend that organizations:
– Hunt for BRICKSTORM and similar backdoors on systems without EDR coverage
– Monitor network appliances that may not have traditional security tools
– Implement comprehensive logging and monitoring across all network devices
– Regularly audit system startup files and configurations
This campaign highlights the evolving sophistication of state-sponsored cyber espionage and the need for enhanced security measures across critical infrastructure and high-value targets.
