Technical Threat Advisory | CVE-2026-45675
This technical threat advisory covers LDAP and OAuth first-user race condition, allowing unauthorized admin privilege escalation in Open WebUI.
This threat was originally discovered by Sanaan Fayaz Wani from the Cyber Florida SOC and is now recognized as an official CVE.
Chrome Zero-Days Threat Advisory

I. Introduction
On 13th March, Google pushed out an emergency security patch to address a pair of critical zero-day vulnerabilities used by attackers to actively exploit the Google Chrome web browser. CVE-2026-3909 and CVE-2026-3910 both carry a high severity CVSS score of 8.8 (a standardized way to measure vulnerabilities’ severity). Both have been confirmed and recognized by Google and Cybersecurity and Infrastructure Security Agency (CISA).
Due to the nature of these flaws existing within the foundation of Chromium code base, that caused these vulnerabilities to be exploited, the attack surface extends beyond Google Chrome. Any browser or application utilizing the Chromium engine is affected, common examples include:
- Brave
- Opera
- Vivaldi
- Microsoft Edge
The vulnerabilities target two distinct core components:
- CVE-2026-3909 (Skia Out-of-Bounds Write): An out-of-bounds memory write vulnerability in Skia 2D graphics library, allowing an attacker to remotely corrupt memory leading to browsers crashing or further exploited.
- CVE-2026-3910 (Inappropriate implementation in V8): A severe critical code injection and memory buffer vulnerability within the V8 JavaScript engine, allowing a remote attacker to execute arbitrary code.
Since these attacks only require a simple click from a victim or to visit a malicious webpage, the risk is immediate; users are urged to update their browsers to mitigate any potential threats.
II. Technical Analysis
Both of these zero-day vulnerabilities target the renderer process, a sandboxed environment responsible for parsing HTML, executing JavaScript, and drawing visual elements on the screen. Since the renderer handles a lot of untrusted data on the web, it is a primary and common target for browser exploitation.
To understand the severity of CVE-2026-3909 and CVE-2026-3910, it is important to look at how the foundational architecture of the Chromium engine manages untrusted web content.
CVE-2026-3909:
Skia Out-of-Bounds (OOB) Write: Skia is a foundational open source 2D graphics library used by Chromium. It renders all visual elements on a webpage: SVG (Scalable Vector Graphics) paths, HTML elements, CSS borders and web fonts.
- The Vulnerability: An Out-of-Bounds (OOB) write occurs when a program writes data past the intended boundary of an allocated memory buffer. In the case of CVE-2026-3909, a logical flaw in how Skia calculates the memory requirements for specific, complex graphic rendering tasks (likely related to path stroking, matrix transformations, or clipping bounds) results in the allocation of a heap buffer that is too small for the resulting data.
- An attacker cannot simply crash the browser; they must control the crash to hijack the system. To exploit this Skia flaw, an attacker could use JavaScript to meticulously arrange the browser’s memory layout, also known as “heap grooming” technique. By precisely positioning specific data structures adjacent to the vulnerable Skia buffer, the attacker triggers the OOB to write to overwrite the neighboring data.
- The attacker’s goal is to overwrite a function pointer or a C++ virtual table (vtable) pointer. Once the browser attempts to use that corrupted pointer for a subsequent graphic operation, the execution flow is redirected to the attacker’s malicious shellcode, granting them control over the renderer process.
CVE-2026-3910
V8 Inappropriate Implementation: V8 is Google’s JavaScript and WebAssembly engine. V8 has a multi-tiered architecture, which relies on an interpreter and “Just-In-Time” optimizing compiler.
- The Vulnerability: As JavaScript runs, TurboFan monitors the code. If a function is executed repeatedly, TurboFan compiles it into highly optimized machine code. To do this quickly, TurboFan makes strict assumptions (speculative optimization) about the types of variables being used based on past behavior. “Inappropriate implementation” indicates a critical bug where TurboFan’s internal logic incorrectly models the side-effects of a specific JavaScript operation, causing it to drop essential security boundaries (like bounds checks or type checks) in the optimized code.
- By feeding the optimized function an unexpected data type, the attacker intentionally violates TurboFan’s assumptions. Since the safety checks were compiled out, the engine experiences “type confusion.” For example, the V8 engine might be tricked into treating a raw integer as a memory pointer, or treating a standard array as an array of executable objects.
- Once type confusion is achieved, the attacker uses it to construct an arbitrary memory read and an arbitrary memory write. The attacker can now scan the V8 heap, locate executable memory pages (often utilizing WebAssembly memory allocations, which are marked as Read/Write/Execute), inject their malicious payload, and execute it.
III. Remediation and Mitigation
Since CVE-2026-3909 and CVE-2026-3910 are being actively exploited in the wild and require no user interaction beyond visiting a malicious webpage, organizations must prioritize immediate remediation.
1. Immediate Remediation: Software Updates
The only definitive method to eliminate the risk posed by these vulnerabilities is to update the affected software. Security and IT operations teams should utilize automated patch management systems to push these updates across their respective networks.
- Google Chrome: Verify that all endpoint deployments of Google Chrome are updated to the following versions (or later):
Windows and macOS: Version 146.0.7680.75 or 146.0.7680.76
Linux: Version 146.0.7680.75
- Chromium-Based Browsers: Ensure that all other approved browsers utilizing the Chromium engine (e.g., Microsoft Edge, Brave, Opera, Vivaldi) are updated to their respective vendors’ patched versions.
- Electron Applications: Monitor vendor advisories for desktop applications built on the Electron framework (e.g., Slack, Microsoft Teams) and apply updates as they are released, as these applications bundle the vulnerable Chromium components.
2. Threat Detection and Hunting
Security Operations Centers (SOC) should continue to ensure their Endpoint Detection and Response (EDR) platforms are configured to monitor for anomalous behavior originating from browser processes. Specifically, analysts should hunt for:
- Unexpected child processes spawning from chrome.exe or msedge.exe (e.g., command shells, PowerShell, or unknown executables).
- Browser processes attempting to write executable files to disk outside of standard download directories.
- Unexpected network connections initiated by the browser to known Command and Control (C2) infrastructure following a browser crash event.
- Monitor for unexpected chrome.exe crashes and Ensure the website or external website is legible.
VII. References
https://nvd.nist.gov/vuln/detail/CVE-2026-3910
https://nvd.nist.gov/vuln/detail/CVE-2026-3909
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html
https://www.sentinelone.com/vulnerability-database/cve-2026-3910/
https://www.chromium.org/Home/chromium-security/
Threat Advisory created by The Cyber Florida Security Operations Center. Contributing Security Analysts: Taylor Alvarez
Qilin Ransomware – A Double Extortion Campaign

I. Introduction
Ransomware remains one of the most damaging cyber threats to both public and private sectors in the U.S. In 2025, Qilin, also known as “Agenda”, emerged as one of the most active ransomware operations currently targeting organizations worldwide, including U.S. state, local, tribal, and territorial (SLTT) entities [3].
First observed in 2022, Qilin quickly became prominent after the decline of RansomHub in early 2025, absorbing many of its affiliates. Qilin operates under a Ransomware-as-a-Service (RaaS) model, in which a core group of cybercriminals develops, advertises, and leases their tools and infrastructure to other affiliate cybercriminals to conduct attacks. This group also uses a double extortion strategy, meaning that in addition to encrypting data and holding the key for ransom, they steal critical data and threaten to sell or release it as an additional form of leverage against victims [3].
This report provides an overview of Qilin ransomware and offers guidance on protecting against its threat actors. Qilin is a ransomware notorious for targeting critical infrastructure, healthcare, manufacturing, and education sectors by exfiltrating their data, encrypting their systems, and leaking confidential information to demand a ransom.
Read through to understand the current threat landscape, including Tactics, Techniques & Procedures, Indicators of Compromise, as well as defensive and mitigation strategies that can be implemented to reduce ransomware risk from the Qilin group.
II. Threat Landscape / Targets
Qilin’s targets are selected by its ransomware affiliates based on opportunity and span across multiple sectors, with the most frequently impacted being manufacturing, education, government, healthcare, critical services, and financial services. The chosen industries are strategically targeted for their high financial value, giving Qilin affiliates a better chance to extort larger ransom payments. These incidents have been observed worldwide, although activity has mostly been observed in North America and Europe. Targets that have been compromised share common infrastructure weaknesses, such as large, distributed networks, legacy systems, and misconfigured remote access services [6, 19].
Qilin’s major attack was on a UK-based healthcare organization called Synnovis. The following examples highlight major attacks between June 2022 and August 2025:
- June 2022 – Initial Discovery (Undisclosed Organization)
- The first known Qilin ransomware case was detected when attackers gained access to a company’s Virtual Private Network (VPN) and compromised an administrator account. Using Remote Desktop Protocol (RDP), they pivoted into the organization’s Microsoft System Center Configuration Manager (SCCM) server, establishing persistence for further attacks. No data exfiltration was observed, but three systems were encrypted [6, 9].
- July 2022 – Initial RaaS Appearance as ‘Agenda’
- The group was first observed promoting their Ransomware-as-a-Service (RaaS) tool, named “Agenda,” which was written in the Go programming language and leased to affiliates [2, 20].
- October 2022 – Public Appearance
- Qilin made its first public appearance on a Dedicated Leak Site (DLS) under the name “Agenda,” confirming affiliate operations within the ransomware marketplace [6, 9].
- December 2022 – Technical Evolution
- Qilin was rewritten in the Rust programming language, improving its encryption speed, detection evasion, and cross-platform compatibility [2, 13]
- April 2023 – Manufacturing Sector
- Undisclosed Organization (APAC): A company in the Asia-Pacific region reported being attacked by the new Qilin variant written in Rust. The attackers used SMB, RDP, and WMI for lateral movement and abused default credentials. Approximately 30 GB of data was exfiltrated to MEGA cloud storage over SSL [6, 9].
- January 2024 – Government Sector Attack
- Australian Court System (Australia): Qilin conducted a double-extortion attack targeting the Australian judicial system, exfiltrating sensitive audiovisual court files to pressure the system into paying [6, 19]
- March 2024 – Additional Attacks
- Qilin was linked to additional attacks across different industries and countries, including International Electro-Mechanical Services (U.S.), Felda Global Ventures Holdings Berhad (Malaysia), Bright Wires (Saudi Arabia), PT Sarana Multi Infrastruktur (Indonesia), Casa Santiveri (Spain) [8].
- May 2024 – U.S. Enterprise Attack
- Undisclosed Organization (U.S.): Qilin compromised a U.S.-based enterprise using default credentials and RDP for initial access and lateral movement. Data exfiltration was observed through FTP [9].
- June 2024 – Healthcare Sector Attack
- Synnovis (UK): Qilin demanded a $50 million ransom after attacking Synnovis, a pathology services provider supporting the UK National Health Service (NHS). The attack disrupted operations of multiple hospitals, caused thousands of appointment cancellations, and resulted in the theft of over 400 GB of patient data [1, 10].
- April 2025 – Corporate Sector Attack
- SK Inc. (South Korea): Qilin affiliates breached the servers of SK Inc., a major investment firm, exfiltrating over 1 TB of confidential corporate data that was later leaked online [6].
- April 2025 – Critical Infrastructure Attack
- City of Abilene (Texas, U.S.): A Qilin attack encrypted city systems and exfiltrated approximately 477 GB of data, resulting in one month of disruption to public services, including the public transit network [14].
- May 2025 – U.S. Government Attack
- Cobb County Government (Georgia, U.S.): Qilin claimed responsibility for exposing the personal and legal data of local government employees and citizens. Over 150 GB of files, including autopsy photos, driver’s licenses, and Social Security numbers, were stolen [5][6].
- June 2025 – Manufacturing Sector Attack
- Shinko Plastics (Japan): Qilin was confirmed to be responsible for a ransomware attack on the Japanese manufacturer Shinko Plastics, claiming to have stolen 27GB of files from the company [11].
- July 2025 – Activity Peak
- Qilin became the most active ransomware group worldwide, claiming 73 victims on its DLS, and demonstrating an increase in activity after recruiting new affiliates [7].
- August 2025 – Additional Manufacturing Sector Attacks
- Qilin claimed responsibility for two confirmed ransomware attacks to the manufacturing sector in Japan, those being Nissan Creative Box and Osaki Medical [11].
With 84 victims between August and September of 2025, the Qilin Ransomware-as-a-Service (RaaS) operation became one of the most active ransomware groups [18].
III. Tactics and Techniques
Qilin uses a wide range of Tactics, Techniques, and Procedures (TTPs) to accomplish its goals. They heavily rely on the use of AI-generated content to improve phishing campaigns, create convincing attacks, and avoid detection, be it from harvesting information about their targets or creating believable digital twins. This use of automation and AI-generated content raises the success rate of their attacks [4, 16].
The following table shows their tactics and techniques, along with the corresponding MITRE ATT&CK IDs:
| TACTIC | TECHNIQUE | MITRE ATT&CK ID | DESCRIPTION |
|---|---|---|---|
| Initial Access | Exploit Public-Facing Application | T1190 | Qilin threat actors take advantage of the following FortiOS and FortiProxy vulnerabilities [21]:
• CVE-2024-21762 for remote code execution. • CVE-2024-55591 for bypassing authentication. |
| Initial Access | Spearphishing (Attachments and Links) | T1566 |
Qilin threat actors have been observed delivering malware through malicious email attachments and links. [15] |
| Execution | PowerShell | T1059.001 |
Qilin threat actors utilize embedded PowerShell scripts to deploy the Rust variant of Qilin across VMware vCenter and ESXi servers (enterprise virtualization systems) as well as PsExec (a Windows remote-execution tool used for lateral movement) [22]. |
| Execution | Native API | T1106 |
Qilin calls the Native API function “LogonUserW,” supplying valid stolen credentials embedded in its configuration. Since the credentials are valid, Windows creates a normal logon session and returns a usable user token. |
| Persistence | AutoStart via Registry Run Keys | T1547.001 |
After executing, Qilin creates a RunOnce registry entry called “aster” that points to enc.exe, which is a copy of the malware dropped in the public folder. This forces Windows to automatically run the ransomware one more time on the next reboot [23]. |
| Persistence | WinlogonBased AutoStart | T1547.004 |
Qilin ransomware alters Winlogon settings, so Windows automatically runs Qilin executables whenever a user signs in [23]. |
| Persistence | Allowing Network Sharing to Encrypt More Files | T1112 |
Qilin ransomware alters registry settings to make admin-mapped network drives visible on all processes, giving much more access to shared folders, file servers, and network storage that can be used to encrypt data for ransom [23]. |
| Privilege Escalation | Exploitation for Privilege Escalation (BYOVD) | T1068 |
Qilin threat actors may exploit vulnerabilities in legitimate but vulnerable signed drivers (Bring Your Own Vulnerable Driver) or other software components to gain higher privileges on compromised hosts, potentially achieving kernel-level access and disabling security controls to facilitate ransomware deployment [23]. |
| Privilege Escalation | Valid Accounts: Domain Accounts | T1078.002 |
Qilin threat actors pivot from a lowaccess Citrix login to a high-privileged leaked/stolen Active Directory account using RDP (a remote-login tool that provides full desktop access), allowing them to push system-wide changes using GPO (Group Policy Objects) to deploy Qilin across the network [23]. |
| Defense Evasion | Delete Artifacts | T1562 / T1070 |
Qilin hides activity by clearing Windows Event Logs, deleting or timestomping files, and self-deleting malware to hinder forensic analysis [16]. |
| Discovery | Cloud Service Dashboard & Backup Discovery | T1538 / T1083 | Qilin threat actors review cloud admin portals to keep track of users, their roles, and whether protections like multifactor authentication are enabled, then search SharePoint, file shares, and backup consoles to locate backup paths, credentials, and snapshots, preparing to disable recovery and prioritize targets [24] |
| Lateral Movement | Remote Services | T1021.002 | Qilin raises MaxMpxCt in Windows to help it spread faster across the network. It embeds PsExec and drops it in %Temp% under a random name to avoid file-based detection [25]. |
| Exfiltration | Exfiltration Over Web Service/Cloud | T1567 | Qilin threat actors zip stolen files into archives using WinRAR. They then open Chrome in Incognito (so the browser would not save history) and upload those ZIP files to easyupload.io, a public file-sharing site, to make it seem like normal HTTPS web traffic [26]. |
| Impact | Data Encrypted for Impact & VSS Deletion | T1486 / T1490 | Qilin threat actors use stolen ScreenConnect consoles to push Qilin to many customers, disable backups to block restores, force Safe Mode with networking so security tools would not start, and delete Volume Shadow Copies to kill rollbacks. They also wipe event logs to hide activity, map more machines to prioritize targets, set a ransom-note wallpaper for leverage, use symbolic links to speed encryption, selfdelete to erase evidence, and encrypt each tenant with a unique 32-character password so one decryptor cannot be reused across victims [26]. |
Table 1. MITRE ATT&CK Techniques Associated with Qilin Ransomware
IV. Adversary Tools and Services
Attackers using Qilin usually gain initial access by using valid accounts, often taken from credential dumps or phishing pages. Once the target is compromised, they move to reconnaissance by using VPN or RDP access to discover endpoints connected to the domain and to map the network, domain trusts, and backup servers for useful targets [18].
In the next stage of the attack chain, attackers harvest credentials with tools such as Mimikatz, search browsers and backup systems for secrets, and abuse those credentials to obtain escalated privileges and to move laterally. Additionally, they deploy legitimate RMM and remote-access software (AnyDesk, ScreenConnect, Splashtop, Atera, etc.) routinely to manage compromised hosts and to load the stage for later activity, and file-transfer utilities (Cyberduck, WinSCP) and common admin applications (mspaint, notepad, iexplore) to scan and harvest for information [18].
To evade detection, Qilin actors use BYOVD (bring-your-own vulnerable driver) exploits, enable Restricted Admin, disable PowerShell-based AMSI/TLS, and disable TLS certificate validation. To tunnel C2 traffic, they use SOCKS proxy DLLs or COROXY implants, sometimes hidden behind RMM infrastructure and legitimate cloud services. For persistent remote access, they were observed using Cobalt Strike and SystemBC [18].
In one recent instance, Qilin actors employed a hybrid approach. They made use of a crossplatform Linux ransomware binary, spreading and executing it on Windows endpoints through remote-management services or safe file transfer. As a result, the group’s presence was amplified on Windows, Linux, and virtualized environments. Altogether, these capabilities make Qilin a significantly dangerous threat [18].
Figure 1. Attack Chain for Qilin Ransomware
V. Indicators of Compromise (IOCs) and Detection Indicators
The table below presents the exact artifacts Qilin used, consisting of: Phishing links and a lookalike ScreenConnect domain, specific installer paths, file hashes of the ransomware and the Veeam exploit tool, Tor/C2 IPs, and the ransom note path. Taken from the GitHub page posted by Sophos Labs called “Ransomware-Qilin-STAC4365.csv” [17], these indicators show how initial access was gained, how tools were deployed, and where encryption and data theft occurred.
| Indicator | Data | Description |
|---|---|---|
|
File Path Name |
C:Users <username> Documents <MSPname> .exe |
Qilin runs code on Windows directly through an executable. The .exe file showed that the ransomware binary was saved and executed as a harmless-looking file in the user’s documents folder, named after the MSP (Managed Service Provider). |
|
SHA256 |
fdf6b0560385a6445bd399eba03c86 |
Hashes representing a different Qilin ransomware executable. They can be traced to the exact malware file, which can help defenders block them. |
|
SHA256 |
0b9b0715a1ffb427a02e61ae8fd11c |
Hashes representing a different Qilin ransomware executable. They can be traced to the exact malware file, which can help defenders block them. |
|
SHA256 |
9da70c521b929725774c3980763a4 |
Hashes representing a different Qilin ransomware executable. They can be traced to the exact malware file, which can help defenders block them |
|
SHA256 |
b52917b0658cd2a9197e6bb62bade |
Hashes representing a different Qilin ransomware executable. They can be traced to the exact malware file, which can help defenders block them. |
|
SHA256 |
ef3e42e5fa24acaee2428ff0118feb2b |
Hashes representing a different Qilin ransomware executable. They can be traced to the exact malware file, which can help defenders block them. |
|
URL |
hxxps[:]//b8dymnk3.r.us-east1.awstrack[.]me/L0/https[:]%2F%2 Fcloud.screenconnect[.]com.ms%2 FsuKcHZYV/1/010001948f5ca748- c4d2fc4f-aa9e-40d4-afe9- bbe0036bc608- 000000/mWU0NBS5qVoIVdXUd4 HdKWrsBSI=410 |
Represents a phishing link hosted on Amazon SES. When clicked, this URL will lead users to a fake ScreenConnect site used for credential and session theft. |
|
URL |
hxxps[:]//cloud.screenconnect[.]co m.ms/suKcHZYV/1/010001948f5ca 748-c4d2fc4f-aa9e-40d4-afe9- bbe0036bc608- 000000/mWU0NBS5qVoIVdXUd4 HdKWrsBSI=410 |
Represents a fake URL used to impersonate ScreenConnect. Qilin threat actors distribute their malware pretending to be ScreenConnect updates. |
|
File Path |
C: Windows SystemTemp ScreenConnect 24.3.7.9067 ru.msi |
A fake ScreenConnect installer used by Qilin attackers to deploy additional payloads to maintain control, disguised as a routine client update. |
|
IP |
186[.]2[.]163[.]10 |
Malicious web host IP with phishing links and installer content |
| IP | 92[.]119[.]159[.]30 | Russian IP that leads to a Russian-hosted server the attacker used to connect to their fake ScreenConnect instance. |
| IP | 109[.]107[.]173[.]60 | Command-and-Control (C2) host used by the attacker as an operational server during the attack. |
| File Path Name |
C: README-RECOVER-<victim ID>. txt |
Text file that holds a ransom note written by the Qilin threat actors. |
| IP | 128[.]127[.]180[.]156 | Tor exit nodes, meaning the attackers routed their traffic through the Tor network to hide their real location. These Tor IPs appeared when they accessed the ScreenConnect server instead of their actual IP addresses. |
| IP | 109[.]70[.]100[.]1 | Tor exit nodes, meaning the attackers routed their traffic through the Tor network to hide their real location. These Tor IPs appeared when they accessed the ScreenConnect server instead of their actual IP addresses. |
| SHA256 | 45c8716c69f56e26c98369e626e0b4 7d7ea5e15d3fb3d97f0d5b6e899729 9d1a |
Hashes that point to the binary Qilin attackers used to exploit Veeam CVE2023-27532. |
| Domain | cloud[.]screenconnect[.]com[.]ms | Fake ScreenConnect domain controlled by Qilin. |
| File Path Name |
C: programdata veeam.exe |
File path that locates where the Veeam exploit tool was saved. |
Table 2. Detection and Monitoring Indicators for Qilin Ransomware
VI. Defensive Strategies & Best Practices
a. Initial Compromise
Threat actors using Qilin RaaS (Ransomware-as-a-Service) packages gain access to enterprise networks through spear-phishing campaigns targeting the C-suite. This can look like emails from unknown users or domains encouraging executives to click on malicious attachments or links designed to replicate legitimate domains. Threat actors also take advantage of legitimate cloud storage services such as OneDrive or Google Drive, making detection more difficult and reinforcing the need for users to recognize suspicious behavior. Staying up to date with security awareness training will equip users with the knowledge to identify typosquatting and report these social engineering attempts, lowering the likelihood of being impacted [3].
b. Reinforce Password Security Policies
Reports from SentinelOne have shown that threat actors were able to gain access to systems with administrator capabilities by exploiting default or weak access credentials. Disabling default credentials and following NIST password security guidance will make it more difficult to gain access to critical systems. NIST 800-53 recommended controls include requiring at least 15- character passwords for privileged accounts, at least 8-character passwords for standard accounts, and comparing passwords against compromised credential databases [15].
c. Diversifying Authentication Methods
Implementing MFA (Multi-Factor Authentication) as well as encouraging passwordless authentication methods like biometrics, hardware tokens, and one-time passcodes will lower the likelihood of a system being accessed if a password is compromised. This implementation is crucial for remote work, as this is a common vector for the abuse of these services [15].
d. Threat Monitoring Tools
Investing in security infrastructure, including EDR, SIEM, and email security tools, specifically those with anti-ransomware capabilities, will aid security engineers in detecting these attacks by analyzing attachments and links for malicious behavior, using behavioral heuristics, comparing file hashes, and detecting lateral movement. Additional defensive measures include securing open ports and performing regular patch and vulnerability management [4].
e. Bolstering Security Defenses
Bolstering security defenses is critical in defending against this ransomware, as users of this tooling are known to abuse remote access through open RDP ports, SSH, VPNs, as well as remote execution to further infiltrate the network. Qilin ransomware is known to exploit unpatched systems, including open ports and services such as Citrix, virtualization, network, and cloud solutions. Keeping up to date with routine software and vulnerability patches will harden devices and limit potential threat vectors that malicious actors can exploit. In instances where these tools must remain available for employees, implementing adaptive security methods (time, geolocation, IP reputation, etc.) will lessen the likelihood of the network being infiltrated without detection [4].
VII. References
[1] BankInfoSecurity. (2024, June 17). UK Pathology Lab Ransomware: Attackers Demanded $50 Million. https://www.bankinfosecurity.com/uk-pathology-lab-ransomware-attackersdemanded-50-million-a-25559
[2] Barracuda. (2025, July 18). Qilin ransomware is growing, but how long will it last? https://blog.barracuda.com/2025/07/18/qilin-ransomware-growing
[3] Center for Internet Security (CIS). (2025, September 11). Qilin: Top Ransomware Threat to SLTTs in Q2 2025. https://www.cisecurity.org/insights/blog/qilin-top-ransomware-threat-to-slttsin-q2-2025
[4] Check Point Software. (2025, July 8). Qilin Ransomware (Agenda): A Deep Dive. https://www.checkpoint.com/cyber-hub/threat-prevention/ransomware/qilin-ransomware/
[5] Cobb County Government. (2025, May 23). Notice of the Cobb County Board of Commissioners Cyber Security Event. https://www.cobbcounty.gov/communications/news/notice-cobb-county-board-commissionerscyber-security-event
[6] CybelAngel. (2025, July 16). Inside Qilin: The Double Extortion Ransomware Threat. https://cybelangel.com/blog/qilin-ransomware-tactics-attack/
[7] Cyble. (2025, August 12). Ransomware Landscape July 2025: Qilin Stays on Top as New Threats Emerge. https://cyble.com/blog/ransomware-groups-july-2025-attacks/
[8] Cyberint. (2025, July 10). Qilin Ransomware: Get the 2025 Lowdown. https://cyberint.com/blog/research/qilin-ransomware/
[9] Darktrace. (2024, July 4). A Busy Agenda: Darktrace’s Detection of Qilin Ransomware-as-aService Operator. https://www.darktrace.com/blog/a-busy-agenda-darktraces-detection-of-qilinransomware-as-a-service-operator
[10] HIPAA Journal. (2024, June 22). Ransomware Group Leaks Data from 300 Million Patient Interactions with NHS. https://www.hipaajournal.com/care-disrupted-at-london-hospitals-due-toransomware-attack-on-pathology-vendor/
[11] Industrial Cyber. (2025, October 08). Qilin hackers claim responsibility for Asahi cyberattack, allege theft of 27 GB of data amid ongoing investigation. https://industrialcyber.co/ransomware/qilin-hackers-claim-responsibility-for-asahi-cyberattackallege-theft-of-27-gb-of-data-amid-ongoing-investigation/
[12] National Institute of Standards and Technology (NIST). (2025, August 20). How Do I Create a Good Password? https://www.nist.gov/cybersecurity/how-do-i-create-good-password
[13] Quorum Cyber. (n.d.). Agenda Ransomware Report. https://www.quorumcyber.com/malware-reports/agenda-ransomware-report/
[14] S-RM. (2025, July 16). Ransomware in Focus: Meet Qilin. https://www.srminform.com/latest-thinking/ransomware-in-focus-meet-qilin
[15] SentinelOne. (2025, September 17). Agenda (Qilin). https://www.sentinelone.com/anthology/agenda-qilin/
[16] Sophos. (2025, April 1). Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream. https://news.sophos.com/en-us/2025/04/01/sophos-mdr-tracks-ongoingcampaign-by-qilin-affiliates-targeting-screenconnect
[17] SophosLabs. (n.d.). Ransomware-Qilin-STAC4365 Indicators of Compromise (IoCs). GitHub Repository. https://github.com/sophoslabs/IoCs/blob/master/Ransomware-QilinSTAC4365.csv
[18] The Hacker News. (2025, October 27). Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid Attack. https://thehackernews.com/2025/10/qilin-ransomwarecombines-linux-payload.html
[19] Tripwire. (2024, June 20). Qilin Ransomware: What You Need to Know. https://www.tripwire.com/state-of-security/qilin-ransomware-what-you-need-know
[20] U.S. Department of Health and Human Services (HHS). (2024, June 18). Qilin Threat Profile (TLP: CLEAR). https://www.hhs.gov/sites/default/files/qilin-threat-profile-tlpclear.pdf
[21] HIPAA Journal. (n.d.). Qilin Ransomware Group Exploiting Critical Fortinet Flaws. https://www.hipaajournal.com/qilin-ransomware-group-exploiting-critical-fortinet-flaws/
[22] BushidoToken. (2024, June). Tracking Adversaries: Qilin RaaS. https://blog.bushidotoken.net/2024/06/tracking-adversaries-qilin-raas.html
[23] Trend Micro. (2022). New Golang Ransomware, Agenda, Customizes Attacks. https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizesattacks.html
[24] ThreatLocker. (n.d.). Qilin Ransomware’s Newest Tactics: Widespread Encryption by Any Means Necessary. https://www.threatlocker.com/blog/qilin-ransomwares-newest-tacticswidespread-encryption-by-any-means-necessary
[25] Picus Security. (n.d.). Qilin Ransomware. https://www.picussecurity.com/resource/blog/qilin-ransomware
[26] CyberSecurityNews. (2025). Qilin Operators Mimic ScreenConnect Login Page. https://cybersecuritynews.com/qilin-operators-mimic-screenconnect-login-page/
Threat Advisory created by The Cyber Florida Security Operations Center. Contributing Security Analysts: Eduarda Koop, Waratchaya Luangphairin, and Isaiah Johnson
BRICKSTORM APT Intrusion Campaign

I. Introduction
BRICKSTORM is a Golang-based backdoor used by the Chinese state-sponsored group, UNC5221 (also known as UTA0178 and Red Dev 61), to quietly maintain long-term access to enterprise and government networks. It is a cross-platform threat that targets Windows, Linux, and BSD-based systems, with a particular focus on edge appliances and remote access infrastructure.
Identified by Mandiant (Google Cloud) in March 2025, this malware has been linked to multiple espionage incidents in the US, including attacks on law firms, Software-as-a-Service (SaaS) providers (companies that offer software applications over the internet), and technology companies.
What makes BRICKSTORM so dangerous is the emphasis on stealth and persistence. Mandiant uncovered one case that revealed BRICKSTORM included a built-in “delay” timer that waited for a specific (hardcoded) date before contacting its command-and-control server, which meant that the threat actor was actively monitoring and capable of adapting their tactics to maintain persistence. Mandiant averages the dwell time for BRICKSTORM malware to be 393 days before detection, highlighting just how effective this backdoor malware can be at evading detection.
Once compromised, BRICKSTORM threat actors will not only compromise the entire environment of their target organization but also the organization’s connections, thereby expanding their attack surface and reaching beyond the initial target.
This advisory will cover what BRICKSTORM is, its targets, Tactics Techniques & Procedures, tools and services used, Indicators of Compromise, as well as mitigation strategies to protect against BRICKSTORM.
II. Target
Legal Services / Law Firms
U.S. law firms and legal services organizations, especially those specializing in mergers and acquisitions, international trade, and government contracting, are primary targets for BRICKSTORM, as these areas provide access to sensitive information about U.S. economic and national security matters [12]. These firms are a valuable source of private/internal communications, transaction records, and trade intelligence that provide strategic insight into U.S. economic and national security matters. The motivation behind these attacks is primarily espionage, as the adversary seeks to obtain privileged emails, negotiation strategies, and other confidential materials that can be used for political or trade advantage. Reporting shows that these campaigns are not short-term, financially driven operations, but long-term intelligence collection efforts that remain active for extended periods, often through persistent access in internal document systems and email servers.
Technology Firms / Intellectual Property-Rich Companies
Technology firms, software vendors, and R&D organizations attract BRICKSTORM due to their proprietary source code and intellectual property. These companies are particularly attractive to groups like these because they develop widely used enterprise and security products that can be leveraged for future exploits. The primary motive behind these attacks is espionage. Additionally, the capability development involves stealing source code and technical data to exploit unidentified vulnerabilities and weaponize them for future offensive operations. Evidence from recent incidents shows the group exploiting virtualization management systems and appliance software to access internal build systems and code repositories. Some of the techniques most frequently used by this group include cloning domain controllers in order to extract credentials offline and using SOCKS proxies for lateral movement, which suggests a deliberate focus on exploiting the development and management infrastructure for persistent/long-term access. [13]
SaaS Providers / Business Process Outsourcers (BPO)
SaaS providers and BPOs are increasingly targeted because compromising a single provider can expose multiple customer environments. These organizations are targeted because the ability to compromise one provider can give these attackers indirect access to many customer environments. The highlight of their motivation still remains espionage, with a focus on supply chain infiltration rather than direct theft. By utilizing tactics such as phishing, social engineering, or exploiting vulnerabilities in the service provider’s infrastructure, adversaries can embed themselves and quietly collect intelligence from a wide range of downstream organizations without triggering immediate detection. [3] Recent investigations indicate that the campaign’s activity within this sector mirrors other China-linked supply chain operations, which also have the key goal of maintaining stealthy persistence to enable long-term surveillance and selective data exfiltration from compromised environments.
Infrastructure / Appliances & Virtualization Management Systems
Network appliances, VPN gateways, firewalls, and virtualization platforms such as VMware vCenter and ESXi are a key focus for BRICKSTORM. These systems are attractive because they often fall outside the visibility of standard endpoint protection and can be used to maintain deep persistence due to the lack of oversight. The motivation is espionage and operational dominance within these target environments, allowing the attackers to harvest credentials, clone virtual machines for offline analysis, and establish covert tunnels for sustained undetected access. Security analysts have identified BRICKSTORM binaries written in Go, which are tailored to operate within appliance and management systems. The use of SOCKS proxying and DNS-over-HTTPS for encrypted communication enables BRICKSTORM to maintain stealthy and persistent access, aligning with their goals of long-term surveillance and data exfiltration. These campaigns frequently initiate with the exploitation of zero-day vulnerabilities in identified perimeter appliances. To maintain a minimal footprint and evade detection, BRICKSTORM employs sophisticated strategies, including customized malware, secure communication channels, and adaptive evasion techniques, underscoring a calculated approach aimed at achieving long-term infiltration and control. [10,14]
III. Tactics and Techniques
The threat actors behind BRICKSTORM employ sophisticated techniques from initial access to exfiltration in order to complete their mission. The following section outlines the MITRE ATT&CK tactics and techniques observed in use by BRICKSTORM [5,11]:
| TACTIC | TECHNIQUE | MITRE ATT&CK ID | DESCRIPTION |
|---|---|---|---|
| Initial Access | Exploit Public-Facing Application | T1190 | Adversaries may exploit vulnerabilities or misconfigurations in internet-facing systems to gain initial network access. |
| Execution | Command and Scripting Interpreter | T1059 |
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. |
| Persistence | Server Software Component: Web Shell | T1505.003 |
Adversaries may backdoor web servers with web shells to establish persistent access to systems. |
| Persistence | Boot or Logon Autostart Execution | T1547 |
Adversaries may configure systems to automatically execute a program during system boot or logon. |
| Credential Access | Credentials from Password Stores | T1555 |
Adversaries may search for common password storage locations to obtain user credentials. |
| Credential Access | OS Credential Dumping | T1003 |
Adversaries may attempt to dump credentials to obtain account login and credential material. |
| Lateral Movement | Remote Services: SSH | T1021.004 |
Adversaries may use valid accounts to log into remote machines using Secure Shell (SSH) and perform actions. |
| Defense Evasion | Obfuscated Files or Information | T1027 |
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or obfuscating its contents. |
| Command and Control | Application Layer Protocol: Web Protocols | T1071.001 |
Adversaries may communicate using application layer protocols associated with web traffic. |
| Command and Control | Application Layer Protocol: DNS over HTTPS | T1071.004 |
Adversaries may communicate using the Domain Name System (DNS) application layer protocol. |
| Exfiltration | Exfiltration Over C2 Channel | T1041 | Adversaries may steal data by exfiltrating it over an existing command and control channel. |
Table 1. MITRE ATT&CK Techniques Associated with BRICKSTORM
Initial Access
Initial access often begins with the compromise of edge devices and public-facing applications. In at least one of the observed cases, the threat actors have obtained initial access by exploiting unknown, unpatched vulnerabilities, CVE-2024-21893 and CVE-2024-21887, which involve a command injection vulnerability and an authentication bypass in web components of Ivanti Connect Secure and Ivanti Policy Secure. [5, 6, 7]
Execution
Once a foothold is established, BRICKSTORM can accept web-based commands and execute OS commands, returning HTTP responses with the command output. This approach gives threat actors interactive control without the need for interactive shells. BRICKSTORM also blends in with the target environment by matching naming conventions and even functionality in order to masquerade as legitimate activity. Together, these techniques make detection significantly harder. [5]
Persistence
After execution, BRICKSTORM establishes persistence by installing an in-memory Java Servlet filter called BRICKSTEAL, which intercepts and decodes web authentication traffic and harvests credentials. Because BRICKSTEAL is loaded in the RAM and not on disk, it is stealthier and will not show up on simple file scans. Additionally, it modifies startup scripts, such as init.d, rc.local, or systemd, to survive any reboots. [2,5]
Credential Access & Privilege Escalation
BRICKSTORM harvests passwords from secret stores and leverages in-memory credential dumping in order to escalate privileges and gain access to administrator infrastructure. In several of the observed cases, the malware targeted password vaults and configuration repositories within virtual machines and cloud environments to extract service account credentials and API tokens. BRICKSTORM was also observed collecting credentials from both volatile memory and encrypted stores, which provides access to high-privilege accounts. After gaining access to credentials, the group targets domain controllers, virtualization hosts, and backup systems to escalate privileges, then uses those privileges to move laterally and authenticate to additional systems and interfaces. [5]
Lateral Movement
BRICKSTORM moves laterally through the network by using SSH (secure, encrypted remote-shell access) and masking their activity as routine administrative behavior. The threat actors, after compromising valid credentials, connect via SSH from compromised hosts to internal systems to transfer files, deploy tools, and execute commands, while avoiding visible interactive shells. SSH is also remotely enabled through vCenter’s Appliance Management Interface (VAMI), allowing the threat actors to create temporary local accounts, which are then removed to erase any activity traces. [2,5]
Defense Evasion
To evade detection from signature-based and static analysis, BRICKSTORM obfuscates and modifies its variants for each target. The malware is compiled as Go binaries (single-file executables produced by the Go compiler that contain everything it needs to run, even the libraries and run-time) using obfuscation tools that strip out any identifiable strings and symbols to prevent matches with known indicators, and it also executes payloads in memory, deletes installers after use, and masks malicious functions within legitimate processes. Together, these approaches make file-hash or signature-based detection even more challenging. [5]
Command and Control (C2)
BRICKSTORM blends C2 traffic into normal web traffic by using HTTP/HTTPS and encrypted channels to send commands and payloads. The threat actors establish a SOCKS proxy tunnel to move through the compromised system and access any internal services, while hiding C2 activity (via DNS-over-HTTPS) and rapidly rotating short-lived cloud servers (via ephemeral infrastructure), making tracking their servers difficult and traffic appear routine. [9]
Exfiltration
BRICKSTORM threat actors exfiltrate data out of the affected systems by using the same channels used for command and control (C2). The SOCKS proxy tunnel forwards their workstation into the victim network, giving them direct access to pull files from internal shares, code repositories, and endpoints. Additionally, a common theme of these threat actors is to access email accounts and mailboxes of key people in their target organization. [3] They abuse Microsoft Entra ID (formerly Azure Active Directory) applications that are configured with weak permissions, such as mail.read or full_access_as_app, to access the mailboxes of target accounts. [2, 9]
IV. Adversary Tools and Services
BRICKSTORM combines custom-built malware, opensource libraries, and legitimate internet services to maintain long-term access and hide their activity across targeted networks. The following list contains tools and services associated with the BRICKSTORM campaign along with reasoning behind why it is part of the campaign:
1. Go ELF Backdoor (Pg_update, Listener, Vmprotect)
A Golang-based implant designed to run directly on F5 BIG-IP appliances. [10] It gives attackers remote control, encrypted communications, and data exfiltration without relying on external dependencies (ideal for stable persistence on embedded Linux systems).
2. Yamux (Golang Multiplexing Library)
Allows attackers to send multiple data streams over one TCP or TLS connection, hiding several operations within a single outbound session. [4]
3. SOCKS Proxy Mechanism
Allows pivoting from the compromised appliance management IP to internal hosts, allowing lateral movement while maintaining stealth. [10]
4. TLS / HTTP/2 (ALPN h2) and WebSocket C2 Channels
Encrypted web protocols that blend with legitimate traffic. The connection upgrades to WebSocket for long-term persistence and control.
5. Exploits for 0-days and Known Vulnerabilities
Used to gain initial access to f5’s BIG-IP management interfaces, especially after F5’s source code theft revealed internal vulnerabilities. [1]
6. Public Code Repositories (China-based)
Reuse of legitimate Golang and networking code from public sources, some of which host malicious projects reused for appliance compromise. [10]
7. Cloud/CDN and DNS-over-HTTPS (DoH) Services
Legitimate cloud platforms (like Cloudflare or Heroku) and encrypted DNS channels abused for C2 traffic, domain hiding, and command relay, making detection more difficult. [2]
V. Indicators of Compromise (IOCs)
According to Mandiant’s threat intelligence report called Another BRICKSTORM:Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors, there is diminishing value for using IOCs to detect BRICKSTORM’s presence [3]. TTP-based hunting is a necessary approach to detect patterns that are unlikely to be detected.
The following table presents a Mandiant-adapted checklist for detecting BRICKSTORM activity and associated adversary behaviors:
| Hunt Objective | Why it matters | Where to Look for Evidence |
|---|---|---|
|
1. Create or update an inventory of all appliances and edge devices |
You can’t hunt what you don’t know exists. Attackers often use private management IPs to send data out of the network. |
Configuration Management Database (CMDB) Asset registry Network Discovery Tools (NMAP, ARP scans) |
|
2. Scan files and backups for BRICKSTORM malware |
Attackers often delete malware from live hosts; however, traces may still be preserved in backups |
Appliance File Systems Backup Stores and Snapshot Images |
|
3. Look for internet traffic from appliances |
Appliances should rarely call unknown Internet hosts. Suspicious outbound traffic may conceal command and control communication |
Firewall logs Domain Name System (DNS) logs Intrusion Detection and Prevention System (IDS/IPS) NetFlow/Proxy logs |
|
4. Watch for appliances connecting to Window Systems |
These devices normally should not log into windows. This could be a sign of lateral movement |
Endpoint Detection and Response (EDR) telemetry Windows Security Event Logs Terminal Services logs Windows Unified Audit Log (UAL) |
|
5. Detect access to passwords and credentials |
Stolen credentials enable privilege escalation or domain compromise. |
Endpoint Detection and Response (EDR) Forensic Snapshots Shellbags Data Protection Application Programming Interface (DPAPI) Artifacts Browser Profile Access Logs |
|
6. Monitor 365 mailbox access |
Actors use mail.read/full_access_as_app to exfiltrate mail at scale, which means they can steal emails and read confidential information. |
Microsoft 365 Unified Audit Log (UAL) OfficeActivity Logs Azure Active Directory (AD) App Registry |
|
7. Check for cloned virtual machines (VMs) |
Attacker can clone a VM to extract sensitive files offline |
vSphere VPXD Logs Virtual Machine (VM) Inventory Datastore Logs |
|
8. Watch for new or deleted local admin accounts |
Short-lived accounts are often created for implant setup or maintaining stealthy access. |
VMware Audit Events Single Sign-on (SSO) Logs Virtual Appliance Management Interface (VAMI) Logs |
|
9. Monitor SSH enablement on appliances |
Attackers often enable SSH to manually deploy or manage implants |
VAMI REST Logs Configuration Change Logs |
|
10. Identify unauthorized or suspicious VMs |
Malicious actors may create fake Virtual Machines to exfiltrate or store stolen data. |
VM Inventory Reports Datastore Object Listings |
Table 2. BRICKSTORM Threat Hunting Reference Table
VI. Recommendations
BRICKSTORM allows attackers to compromise systems and networks while evading detection by common security controls, such as DNS monitoring at the network level. To mitigate these threats, organizations should implement the following defensive strategies:
1. DNS over HTTPS
BRICKSTORM can be configured to operate both with and without DNS over HTTPS (DoH). Therefore, it is recommended that organizations watch for unusual DoH activity to prevent variations of BRICKSTORM that may leverage these services. [8]
2. TLS Inspection
BRICKSTORM can easily blend malicious activity into legitimate HTTPS traffic by using encrypted channels for C2. As a result, organizations should ensure that their TLS inspection detects or blocks nested TLS sessions (encrypted sessions over already encrypted traffic). [8]
3. Behavior-Based Detection
To avoid detection, BRICKSTORM uses the component BRICKSTEAL loaded in the memory, and obfuscates and modifies its variants for each target. Therefore, traditional signature-based detections may fail to detect the backdoor. Organizations should implement EDR solutions capable of performing behavioral anomaly detection to focus on unusual process injections, in-memory Java servlet filters, or unsigned binaries. [3, 5]
4. Principle of Least Privilege
Any device that is internal or internet-facing should be configured to follow the principle of least privilege. Devices should be outbound only to vendor update servers, package repositories, or support endpoints. Therefore, firewalls should be in place to monitor and allow access only to authorized domains and IPs necessary for devices to operate. [3]
5. Patch and Harden Systems
Vendor updates should be applied to all systems, and outbound connectivity should be restricted for management interfaces. [2]
6. Threat Hunting & Detection Logic
Based on the identified TTPs and Indicators of Compromise, organizations are encouraged to perform threat hunts and put in place detection rules to proactively detect BRICKSTORM. [2]
7. Access Controls
SSH is remotely enabled through vCenter’s Appliance Management Interface (VAMI) to allow threat actors to create temporary local accounts. Therefore, MFA should be enforced for vCenter’s Appliance Management Interface (VAMI), while also monitoring VM cloning. Additionally, BRICKSTORM abuses Microsoft Entra ID applications and its permissions, making it fundamental for organizations to review permissions such as mail.read or full_access_as_app. [2,3]
By following these recommendations and defensive strategies, organizations can proactively defend themselves from BRICKSTORM.
VII. References
[1] Cybersecurity and Infrastructure Security Agency. (2025, April). Emergency Directive 26-01: Mitigate vulnerabilities in F5 devices. https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices
[2] Fortinet. (2025, April 10). BRICKSTORM espionage campaign: Threat Signal Report 6204. FortiGuard Threat Intelligence. https://www.fortiguard.com/threat-signal-report/6204/brickstorm-espionage-campaign
[3] Google Threat Intelligence Group. (2025, September 24). Another BRICKSTORM: Stealthy backdoor enabling espionage into tech and legal sectors. Google Cloud Threat Intelligence Blog. https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign
[4] HashiCorp. (n.d.). Yamux: Golang multiplexing library. GitHub repository. https://github.com/hashicorp/yamux
[5] Mandiant (Intelligence Team). (2025, March). BRICKSTORM malware: UNC5221 targets tech and legal sectors in the United States. Picus Security Blog. https://www.picussecurity.com/resource/blog/brickstorm-malware-unc5221-targets-tech-and-legal-sectors-in-the-united-states
[6] National Institute of Standards and Technology. (2023). CVE-2023-46805: Authentication bypass in Ivanti Connect Secure. National Vulnerability Database. https://nvd.nist.gov/vuln/detail/CVE-2023-46805
[7] National Institute of Standards and Technology. (2024). CVE-2024-21887: Command injection vulnerability in Ivanti Connect Secure and Policy Secure. National Vulnerability Database. https://nvd.nist.gov/vuln/detail/CVE-2024-21887
[8] NVISO Labs. (2025, April). BRICKSTORM malware analysis report. NVISO Threat Intelligence Blog. https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf
[10] ReSecurity. (2025, April 15). F5 BIG-IP source code leak tied to state-linked campaigns using BRICKSTORM backdoor. ReSecurity Threat Intelligence Blog. https://www.resecurity.com/blog/article/f5-big-ip-source-code-leak-tied-to-state-linked-campaigns-using-brickstorm-backdoor
[11] The MITRE Corporation. (2025). MITRE ATT&CK framework: Techniques and tactics. https://attack.mitre.org/ 14 of 14
[12] Bloomberg. (2025, September 24). ’Most prevalent’ Chinese hacking group targets tech, law firms. Bloomberg News. https://www.bloomberg.com/news/articles/2025-09-24/-most-prevelant-chinese-hacking-group-targets-tech-law-firms
[13] Burt, J. (2025, September 24). Chinese hackers steal data from U.S. legal, tech firms for more than a year. Security Boulevard. https://securityboulevard.com/2025/09/chinese-hackers-steal-data-from-u-s-legal-tech-firms-for-more-than-a-year/
[14] Lakshmanan, R. (2025, September 24). UNC5221 uses BRICKSTORM backdoor to infiltrate U.S. legal and technology sectors. The Hacker News. https://thehackernews.com/2025/09/unc5221-uses-brickstorm-backdoor-to.html
[15] Arctic Wolf Networks. (2025, October 30). UNC6384 weaponizes ZDI-CAN-25373 vulnerability to deploy PlugX against Hungarian and Belgian diplomatic entities. Arctic Wolf. https://arcticwolf.com/resources/blog/unc6384-weaponizes-zdi-can-25373-vulnerability-to-deploy-plugx/
[14] Google Threat Intelligence Group. (2025, August 25). PRC-Nexus espionage campaign hijacks web traffic to target diplomats. Google Cloud Blog. https://cloud.google.com/blog/topics/threat-intelligence/prc-nexus-espionage-targets-diplomats
[15] Mandiant. (2025, September 24). Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors. Google Cloud Blog. https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign
[16] The Hacker News. (n.d.). UNC5221 uses BRICKSTORM backdoor to infiltrate U.S. legal and technology sectors. https://thehackernews.com/2025/09/unc5221-uses-brickstorm-backdoor-to.html
Threat Advisory created by The Cyber Florida Security Operations Center. Contributing Security Analysts: Waratchaya Luangphairin (June), Eduarda Koop, and Isaiah Johnson



