Brickstorm Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 4, 2025
Last Seen
February 17, 2026

Brickstorm Campaign is a threat campaign tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed December 4, 2025; most recent activity February 17, 2026.

Overview

Brickstorm Campaign is a China-linked espionage operation that uses the Brickstorm malware to conduct cyber espionage. The campaign is described as expansive and ongoing, indicating broad targeting and persistent activity, making it a significant threat to organizations seeking to protect sensitive information.

Related Threat Clusters

  • Chinese Hackers Exploit Dell Zero-Day Flaw CVE-2026-22769 Since Mid-2024

    A Chinese state-backed hacking group, UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines since at least mid-2024. The flaw, tracked as CVE-2026-22769, features a…

    40 articles · Updated February 17, 2026
  • China's Brickstorm Malware Compromises US Critical Networks

    Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…

    10 articles · Updated December 4, 2025

Recent Intelligence Reports

  • Chinese hackers exploiting Dell zero-day flaw since mid — Bleepingcomputer · February 17, 2026
  • Officials warn about expansive, ongoing China espionage threat riding on Brickstorm malware — Cyberscoop · December 4, 2025

CVSS v3.1 Breakdown