Shadowy Campaign Of BrickStorm is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 5, 2025; most recent activity December 5, 2025.
Shadowy Campaign Of BrickStorm is a threat campaign attributed to Chinese hackers that uses the BrickStorm malware to target infrastructure networks. The operation appears focused on infiltrating infrastructure operators, signaling potential espionage or disruption of critical services. The campaign’s significance stems from its targeting of essential infrastructure and the resulting official warnings from the US and Canada.
Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…