CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

vSphere and BRICKSTORM Malware: A Defender's Guide

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 317

As cited

Copy frozen at (site build).

threat intel

vSphere and BRICKSTORM Malware: A Defender's Guide

Google Threat Intelligence Group published research on BRICKSTORM malware targeting VMware vSphere environments, with a focus on hardening strategies to defend virtualized infrastructure. Threat actors exploit weak security architecture, identity design, and limited visibility at the virtualization control plane to establish persistence beneath the guest operating system where traditional security tools are ineffective. Mandiant released a vCenter Hardening Script to help organizations enforce security configurations at the Photon Linux layer and transform the virtualization layer into a hardened environment.

Why it matters: Infrastructure teams managing VMware vSphere environments need to implement hardening controls immediately, as BRICKSTORM-style attacks targeting vCenter Server Appliance can grant attackers administrative control over all managed ESXi hosts and virtual machines, bypassing traditional organizational security tiers and providing access to Tier-0 assets.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

vSphere and BRICKSTORM Malware: A Defender's Guide

Google Threat Intelligence Group published research on BRICKSTORM malware targeting VMware vSphere environments, with a focus on hardening strategies to defend virtualized infrastructure. Threat actors exploit weak security architecture, identity design, and limited visibility at the virtualization control plane to establish persistence beneath the guest operating system where traditional security tools are ineffective. Mandiant released a vCenter Hardening Script to help organizations enforce security configurations at the Photon Linux layer and transform the virtualization layer into a hardened environment.

Why it matters: Infrastructure teams managing VMware vSphere environments need to implement hardening controls immediately, as BRICKSTORM-style attacks targeting vCenter Server Appliance can grant attackers administrative control over all managed ESXi hosts and virtual machines, bypassing traditional organizational security tiers and providing access to Tier-0 assets.

VendorsMicrosoftGoogleVMware
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary