www.volexity.com
VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was misconfigured and allowed unauthorized access via stolen credentials. The attacker used a malware implant called BRICKSTORM, along with a secondary Python reverse shell named AGENTPSD, to maintain persistence. Following the initial detection, VerdantBamboo executed multiple re-entry attempts exploiting different infrastructure weaknesses. The campaign highlights significant vulnerabilities in endpoint detection and response capabilities. Volexity's investigation revealed that the threat actor had previously compromised the MSP's firewall, indicating a broader supply chain attack. The incident underscores the need for improved security measures in managed services. The situation remains critical as VerdantBamboo continues to pose a threat.
Key Points: • VerdantBamboo exploited a misconfigured Egnyte Storage Sync appliance to gain access. • The attack involved a sophisticated multi-stage intrusion with a primary malware implant, BRICKSTORM. • The threat actor successfully re-entered the network multiple times after initial detection.