Sunday, September 13, 2026

Chinese APT VerdantBamboo Targets Appliances with BRICKSTORM Malware

BRICKSTORM is a modular remote access trojan (RAT) originally seen in Golang and later in Rust. It uses a wssoft library with pluggable “tasks” for shell commands, a Socks5 proxy, and a simple web server for file listing.

An incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network.

Instead of talking to Egnyte, the appliance reached out to attacker-controlled domains routed through Cloudflare and made TLS connections to Google’s public DNS, likely using DNS over HTTPS.

Snapshots of the appliance confirmed a compromise. Volexity traced the activity to a Chinese threat actor it calls VerdantBamboo, also tracked as WARP PANDA or UNC5221, and found the BRICKSTORM backdoor among other tools.

On the compromised Storage Sync system, the actor had deployed BRICKSTORM to /usr/sbin and ran it manually by exploiting an unintended sudo configuration for the egnyteservice account.

That sudo setup allowed the low-privileged account to use tee as root, enabling the attackers to write files to protected locations and then execute a cron job briefly to start the implant.

Volexity found BRICKSTORM malware variants also running on a pfSense firewall belonging to the victim’s managed service provider (MSP), with a FreeBSD-compatible build placed in /usr/local/libexec/ipsec and added to startup cron for persistence.

The intrusion timeline stretched back at least 18 months. VerdantBamboo used BRICKSTORM’s proxying ability and stolen credentials to access the victim’s Microsoft 365 environment while appearing to come from the victim’s own SSL VPN IP addresses.

This blending of malicious access with legitimate VPN traffic allowed the actor to evade Conditional Access controls that might otherwise have blocked suspicious logins.

Volexity assessed that the initial compromise likely involved the MSP; the MSP’s pfSense firewall showed multiple compromises, including web shells and a BRICKSTORM implant, suggesting the attacker had root-level access to critical MSP systems.

In September 2025, Volexity responded to suspicious network traffic from a Linux virtual appliance used for Egnyte Storage Sync on a customer’s network.

In addition to BRICKSTORM, Volexity uncovered two previously undocumented malware families. PLENET is a cross-platform backdoor written in .NET Core and compiled to a native binary using Native AOT, which makes analysis harder because the runtime and metadata are embedded in the executable.

Chinese APT VerdantBamboo

PLENET communicates over WebSockets and supports an interactive shell, file operations, remote command execution, and C2 switching. AGENTPSD is a simpler Python-based reverse shell packaged with PyInstaller; Volexity believes it served as a fallback if the primary backdoor failed.

Nameegnyte_host_monitor_client
Size6.4MB (6692728 Bytes)
File TypeELF Executable
MD598ee964edeb5a988c3bba8ea1e57fe0e
SHA1e952c18272efa1c3d73d0a5381bcf443c02743fe
SHA256ee41e06ed96182ce80cd4544a6abd5d7719c4a5c0e5ddb266a83842d39b99b0a

The attackers had placed their backdoor in the /usr/local/libexec/ipsec/ directory and named it blacklist.

After initial remediation, VerdantBamboo returned. The actor used stolen administrative credentials to access the organization’s firewall web interface when it was exposed to the internet, enabled a web-based SSL VPN, and pivoted to deploy PLENET onto a Synology NAS.

Nameovs-dbctl
Size2.5MB (2635736 Bytes)
File TypeELF Executable
MD595dc2289427ed29b8b996d0e3d1b78cb
SHA1f8d93c1769e877aae7e7d5c289a467b5ae371c7a
SHA256eb141a43958802727a6c813452450c10b92704bea4474ee5fd87c0a1be326e2e

Volexity’s forensic work recovered BRICKSTORM on retired virtual machines and confirmed persistence mechanisms across appliances that often lack full EDR coverage, which the attackers exploited deliberately.

Volexity also deployed a Censys query to fingerprint BRICKSTORM C2 infrastructure and observed the actor’s servers go silent in late September 2025, possibly in response to public reporting.

Overall, VerdantBamboo demonstrates operational discipline: targeting edge appliances and MSP infrastructure, leveraging living-off-the-land techniques, and using customized malware and persistence to remain undetected for long periods.

Organizations should monitor unmanaged appliances, enforce MFA for administrative interfaces, restrict VPN and remote management exposure, and coordinate with MSPs to reduce the risk from supply-chain access.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News