CISA Exposes BRICKSTORM Backdoor Linked to China APTs
First seen 5 Dec 2025, 12:43 UTC
•
•81% similarity
•33
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
CISA has disclosed details about the BRICKSTORM backdoor, which is linked to Chinese state-sponsored threat actors. This backdoor targets VMware vSphere environments within government and technology sectors, enabling long-term persistence on compromised systems. Ongoing cyber-espionage activities by these actors have been highlighted in the report.
ThreatCluster AI
How this analysis works