VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers

VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers

First seen 5 Jun 2026, 18:56 UTC Thecyberexpresswww.volexity.com 77% similarity 75.5

Article Content

Browse articles
ThreatCluster

A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was misconfigured and allowed unauthorized access via stolen credentials. The attacker used a malware implant called BRICKSTORM, along with a secondary Python reverse shell named AGENTPSD, to maintain persistence. Following the initial detection, VerdantBamboo executed multiple re-entry attempts exploiting different infrastructure weaknesses. The campaign highlights significant vulnerabilities in endpoint detection and response capabilities. Volexity's investigation revealed that the threat actor had previously compromised the MSP's firewall, indicating a broader supply chain attack. The incident underscores the need for improved security measures in managed services. The situation remains critical as VerdantBamboo continues to pose a threat.

Key Points: • VerdantBamboo exploited a misconfigured Egnyte Storage Sync appliance to gain access. • The attack involved a sophisticated multi-stage intrusion with a primary malware implant, BRICKSTORM. • The threat actor successfully re-entered the network multiple times after initial detection.

ThreatCluster AI

Timeline

2025-09-01
Initial compromise detected
Volexity responded to suspicious traffic from an Egnyte Storage Sync appliance, revealing unauthorized connections.
Volexity
2025-09-01
Malware implants identified
Forensic analysis revealed BRICKSTORM and AGENTPSD were installed on the compromised appliance.
Thecyberexpress
2025-09-01
MSP compromise confirmed
Investigation showed that VerdantBamboo had previously compromised the victim's managed service provider.
Volexity
2026-06-04
Incident response published
Volexity released findings on the 18-month campaign, detailing the attack vectors and persistence methods used by VerdantBamboo.
Volexity
2026-06-04
Security measures recommended
Volexity advised organizations to enhance endpoint detection and response capabilities to prevent similar attacks.
Thecyberexpress

Community

Browse all →