As cited
Copy frozen at (site build).
threat intel
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Volexity discovered that a Chinese threat actor tracked as VerdantBamboo had compromised an Egnyte Storage Sync appliance using the BRICKSTORM malware, with the initial compromise dating back at least 18 months. The actor used the compromised appliance to access the victim's Microsoft 365 environment while evading security controls, and later regained access via stolen firewall credentials to deploy additional malware. Investigation revealed the victim organization had been compromised through a breach of their managed services provider, whose pfSense firewall had also been infected with BRICKSTORM for at least 18 months.
Why it matters: Organizations using Egnyte Storage Sync, pfSense firewalls, and MSP-managed infrastructure face persistent risk from VerdantBamboo; practitioners should investigate long-term network anomalies, review firewall and VPN access logs, and audit MSP security postures to detect similar implants.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
VerdantBamboo: Just Another BRICKSTORM in the Firewall
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Volexity investigated a compromise of an Egnyte Storage Sync system that revealed a Chinese threat actor tracked as VerdantBamboo (also known as WARP PANDA, UNC5221) had maintained access for at least 18 months using the BRICKSTORM backdoor. The actor used the compromised appliance to proxy traffic and evade conditional access policies to reach the victim's Microsoft 365 environment, and later returned with stolen firewall credentials to deploy additional malware. Investigation uncovered that the victim's managed services provider had also been compromised via a BSD variant of BRICKSTORM on its pfSense firewall, likely serving as the initial infection vector.
Why it matters: Organizations relying on storage sync appliances, firewalls, and MSPs are exposed to long-dwell compromises by Chinese state-linked groups that can bypass cloud access controls; practitioners should audit appliance and firewall logs, review MSP access privileges, and hunt for BRICKSTORM and related malware families (PLENET, AGENTPSD) across on-premises and edge infrastructure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Volexity investigated a compromise of an Egnyte Storage Sync system that revealed a Chinese threat actor tracked as VerdantBamboo (also known as WARP PANDA, UNC5221) had maintained access for at least 18 months using the BRICKSTORM backdoor. The actor used the compromised appliance to proxy traffic and evade conditional access policies to reach the victim's Microsoft 365 environment, and later returned with stolen firewall credentials to deploy additional malware. Investigation uncovered that the victim's managed services provider had also been compromised via a BSD variant of BRICKSTORM on its pfSense firewall, likely serving as the initial infection vector.
Why it matters: Organizations relying on storage sync appliances, firewalls, and MSPs are exposed to long-dwell compromises by Chinese state-linked groups that can bypass cloud access controls; practitioners should audit appliance and firewall logs, review MSP access privileges, and hunt for BRICKSTORM and related malware families (PLENET, AGENTPSD) across on-premises and edge infrastructure.
- Source published
- First seen by Cybersecurity Tracker