BRICKSTORM Backdoor Analysis: A Persistent Espionage Threat to European Industries
Essential information
- Published
- 16/04/2025 14:51
- Modified
- 16/04/2025 18:21
- Tags
- 2025-04-16 backdoor brickstorm china-nexus espionage european industries evasion techniques file management network tunneling
- Related entities
- 4 observables, 1 intrusion sets (apt), 4 techniques (mitre), 1 malware, 2 others
Description
This analysis examines BRICKSTORM, an espionage backdoor linked to China-nexus cluster UNC5221. It details newly identified Windows variants, expanding on previous Linux presence. The backdoor, used in long-term espionage campaigns, targets European industries of strategic interest to China. BRICKSTORM provides file management and network tunneling capabilities, using multiple layers of encryption and leveraging cloud providers to evade detection. The analysis covers the backdoor's inner workings, including its command and control infrastructure, protocol details, and evasion techniques. It highlights the persistent nature of these intrusions and the challenges they pose to defensive measures. The document concludes with recommendations for detection and mitigation strategies.