CISA Alerts on Chinese BrickStorm Malware Targeting VMware Servers

CISA Alerts on Chinese BrickStorm Malware Targeting VMware Servers

First seen 4 Dec 2025, 21:46 UTC BleepingcomputerCrnThecyberexpress 84% similarity 33.3

Article Content

Browse articles
ThreatCluster

CISA, in collaboration with the NSA and Canada's Cyber Security Centre, has issued a warning about Chinese hackers using BrickStorm malware to backdoor VMware vSphere servers. The attacks primarily affect government and IT sectors, allowing attackers to access the vCenter management console, steal VM snapshots, and create rogue virtual machines.

ThreatCluster AI

Community

Browse all →