BRICKSTORM is a modular remote access trojan (RAT) originally seen in Golang and later in Rust. It uses a wssoft library with pluggable “tasks” for shell commands, a Socks5 proxy, and a simple web server for file listing.
An incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network.
Instead of talking to Egnyte, the appliance reached out to attacker-controlled domains routed through Cloudflare and made TLS connections to Google’s public DNS, likely using DNS over HTTPS.
Snapshots of the appliance confirmed a compromise. Volexity traced the activity to a Chinese threat actor it calls VerdantBamboo, also tracked as WARP PANDA or UNC5221, and found the BRICKSTORM backdoor among other tools.
On the compromised Storage Sync system, the actor had deployed BRICKSTORM to /usr/sbin and ran it manually by exploiting an unintended sudo configuration for the egnyteservice account.
That sudo setup allowed the low-privileged account to use tee as root, enabling the attackers to write files to protected locations and then execute a cron job briefly to start the implant.
Volexity found BRICKSTORM malware variants also running on a pfSense firewall belonging to the victim’s managed service provider (MSP), with a FreeBSD-compatible build placed in /usr/local/libexec/ipsec and added to startup cron for persistence.
The intrusion timeline stretched back at least 18 months. VerdantBamboo used BRICKSTORM’s proxying ability and stolen credentials to access the victim’s Microsoft 365 environment while appearing to come from the victim’s own SSL VPN IP addresses.
This blending of malicious access with legitimate VPN traffic allowed the actor to evade Conditional Access controls that might otherwise have blocked suspicious logins.
Volexity assessed that the initial compromise likely involved the MSP; the MSP’s pfSense firewall showed multiple compromises, including web shells and a BRICKSTORM implant, suggesting the attacker had root-level access to critical MSP systems.
In September 2025, Volexity responded to suspicious network traffic from a Linux virtual appliance used for Egnyte Storage Sync on a customer’s network.
In addition to BRICKSTORM, Volexity uncovered two previously undocumented malware families. PLENET is a cross-platform backdoor written in .NET Core and compiled to a native binary using Native AOT, which makes analysis harder because the runtime and metadata are embedded in the executable.
Chinese APT VerdantBamboo
PLENET communicates over WebSockets and supports an interactive shell, file operations, remote command execution, and C2 switching. AGENTPSD is a simpler Python-based reverse shell packaged with PyInstaller; Volexity believes it served as a fallback if the primary backdoor failed.
| Name | egnyte_host_monitor_client |
| Size | 6.4MB (6692728 Bytes) |
| File Type | ELF Executable |
| MD5 | 98ee964edeb5a988c3bba8ea1e57fe0e |
| SHA1 | e952c18272efa1c3d73d0a5381bcf443c02743fe |
| SHA256 | ee41e06ed96182ce80cd4544a6abd5d7719c4a5c0e5ddb266a83842d39b99b0a |
The attackers had placed their backdoor in the /usr/local/libexec/ipsec/ directory and named it blacklist.
After initial remediation, VerdantBamboo returned. The actor used stolen administrative credentials to access the organization’s firewall web interface when it was exposed to the internet, enabled a web-based SSL VPN, and pivoted to deploy PLENET onto a Synology NAS.
| Name | ovs-dbctl |
| Size | 2.5MB (2635736 Bytes) |
| File Type | ELF Executable |
| MD5 | 95dc2289427ed29b8b996d0e3d1b78cb |
| SHA1 | f8d93c1769e877aae7e7d5c289a467b5ae371c7a |
| SHA256 | eb141a43958802727a6c813452450c10b92704bea4474ee5fd87c0a1be326e2e |
Volexity’s forensic work recovered BRICKSTORM on retired virtual machines and confirmed persistence mechanisms across appliances that often lack full EDR coverage, which the attackers exploited deliberately.
Volexity also deployed a Censys query to fingerprint BRICKSTORM C2 infrastructure and observed the actor’s servers go silent in late September 2025, possibly in response to public reporting.
Overall, VerdantBamboo demonstrates operational discipline: targeting edge appliances and MSP infrastructure, leveraging living-off-the-land techniques, and using customized malware and persistence to remain undetected for long periods.
Organizations should monitor unmanaged appliances, enforce MFA for administrative interfaces, restrict VPN and remote management exposure, and coordinate with MSPs to reduce the risk from supply-chain access.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





