CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

VerdantBamboo: Just Another BRICKSTORM in the Firewall

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2103

As cited

Copy frozen at (site build).

threat intel

VerdantBamboo: Just Another BRICKSTORM in the Firewall

Volexity discovered that a Chinese threat actor tracked as VerdantBamboo had compromised an Egnyte Storage Sync appliance using the BRICKSTORM malware, with the initial compromise dating back at least 18 months. The actor used the compromised appliance to access the victim's Microsoft 365 environment while evading security controls, and later regained access via stolen firewall credentials to deploy additional malware. Investigation revealed the victim organization had been compromised through a breach of their managed services provider, whose pfSense firewall had also been infected with BRICKSTORM for at least 18 months.

Why it matters: Organizations using Egnyte Storage Sync, pfSense firewalls, and MSP-managed infrastructure face persistent risk from VerdantBamboo; practitioners should investigate long-term network anomalies, review firewall and VPN access logs, and audit MSP security postures to detect similar implants.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

VerdantBamboo: Just Another BRICKSTORM in the Firewall

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

VerdantBamboo: Just Another BRICKSTORM in the Firewall

Volexity investigated a compromise of an Egnyte Storage Sync system that revealed a Chinese threat actor tracked as VerdantBamboo (also known as WARP PANDA, UNC5221) had maintained access for at least 18 months using the BRICKSTORM backdoor. The actor used the compromised appliance to proxy traffic and evade conditional access policies to reach the victim's Microsoft 365 environment, and later returned with stolen firewall credentials to deploy additional malware. Investigation uncovered that the victim's managed services provider had also been compromised via a BSD variant of BRICKSTORM on its pfSense firewall, likely serving as the initial infection vector.

Why it matters: Organizations relying on storage sync appliances, firewalls, and MSPs are exposed to long-dwell compromises by Chinese state-linked groups that can bypass cloud access controls; practitioners should audit appliance and firewall logs, review MSP access privileges, and hunt for BRICKSTORM and related malware families (PLENET, AGENTPSD) across on-premises and edge infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

VerdantBamboo: Just Another BRICKSTORM in the Firewall

Volexity investigated a compromise of an Egnyte Storage Sync system that revealed a Chinese threat actor tracked as VerdantBamboo (also known as WARP PANDA, UNC5221) had maintained access for at least 18 months using the BRICKSTORM backdoor. The actor used the compromised appliance to proxy traffic and evade conditional access policies to reach the victim's Microsoft 365 environment, and later returned with stolen firewall credentials to deploy additional malware. Investigation uncovered that the victim's managed services provider had also been compromised via a BSD variant of BRICKSTORM on its pfSense firewall, likely serving as the initial infection vector.

Why it matters: Organizations relying on storage sync appliances, firewalls, and MSPs are exposed to long-dwell compromises by Chinese state-linked groups that can bypass cloud access controls; practitioners should audit appliance and firewall logs, review MSP access privileges, and hunt for BRICKSTORM and related malware families (PLENET, AGENTPSD) across on-premises and edge infrastructure.

VendorsMicrosoftGoogleSynologyCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary