S9015: BRICKSTORM
BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of other malware, and the exfiltration of data.[1][2][3][4] BRICKSTORM has also been created from a .NET application using ahead-of-time (AOT) compilation to blend in within victim environments.[1] BRICKSTORM was first observed in April 2024.[5] BRICKSTORM has previously been leveraged by People's Republic of China (PRC) state-nexus actors identified as UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE.[6][7][1][8][9][10][3][4]
Security context for executives and security teams
S9015: BRICKSTORM describes [BRICKSTORM](https://attack.mitre.org/software/S9015) is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of other malware, and the exfiltration of data.(Citation: CISA BRICKSTORM UNC5221 AR25-338A February 2026)(Citation: Picus Security BRICKSTORM UNC5221 October 2025)(Citation: Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025)(Citation: Google BRICKSTORM September 2025) [BRICKSTORM](https://attack.mitre.org/software/S9015) has also been ...
Executive priority
S9015: BRICKSTORM is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S9015: BRICKSTORM by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (ESXi, Linux, Network Devices, Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S9015: BRICKSTORM appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
BRICKSTORM
BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of other malware, and the exfiltration of data.[1][2][3][4] BRICKSTORM has also been created from a .NET application using ahead-of-time (AOT) compilation to blend in within victim environments.[1] BRICKSTORM was first observed in April 2024.[5] BRICKSTORM has previously been leveraged by People's Republic of China (PRC) state-nexus actors identified as UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE.[6][7][1][8][9][10][3][4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1027 | Obfuscated Files or Information | BRICKSTORM has utilized Go libraries to include Garble to obfuscate code.[2][4] |
| Enterprise | T1041 | Exfiltration Over C2 Channel | |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`.[7][5][4] BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`.[1] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers.[7][1][2][5][9][4] BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls.[9] |
| Enterprise | T1070.010 | Relocate MalwareSub-technique | BRICKSTORM has copied itself to the `usr/sbin/` folder.[1] |
| Enterprise | T1057 | Process Discovery | BRICKSTORM has the ability to check if it is running as an active child process through the detection of a specific environment variable.[1] |
| Enterprise | T1574.007 | Path Interception by PATH Environment VariableSub-technique | BRICKSTORM has checked hard-coded paths of `/etc/sysconfig/` or `/etc/sysconfig/network` prior to execution and loading file contents from that path.[1] |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | BRICKSTORM has utilized XOR cipher encryption to hide key strings within their code, to include IPv4 addresses of public DNS-over-HTTPS (DOH) servers.[1] |
| Enterprise | T1690 | Prevent Command History Logging | BRICKSTORM has impaired command logging through the use of `dev/null` which prevents generating output from the command and does not wait for input.[1] |
| Enterprise | T1573.002 | Asymmetric CryptographySub-technique | BRICKSTORM has communicated with C2 infrastructure via TLS.[7][1][2][3] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | BRICKSTORM has decoded its encrypted C2 traffic prior to execution.[7][1][2][3][4] BRICKSTORM also has the ability to decode its obfuscated payload before execution.[2] |
| Enterprise | T1543 | Create or Modify System Process | BRICKSTORM has created a new background session and has spawned a child process of a parent process when it determines it is not running in its intended state.[1] |
| Enterprise | T1572 | Protocol Tunneling | BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints.[7][1][2][5][9][3][4] BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket.[1][9][3] |
| Enterprise | T1070.004 | File DeletionSub-technique | BRICKSTORM has the ability to delete files and directories.[1] BRICKSTORM also has deleted installer files after execution to reduce detection.[2][5][9] |
| Enterprise | T1132.001 | Standard EncodingSub-technique | BRICKSTORM has leveraged Base64 to encode C2 communications.[9][3] |
| Enterprise | T1678 | Delay Execution | BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence.[2][9] BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain.[4] |
| Enterprise | T1568 | Dynamic Resolution | BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses.[4] |
| Enterprise | T1105 | Ingress Tool Transfer | BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.[1][5][9][4] |
| Enterprise | T1102 | Web Service | BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io.[4] BRICKSTORM has also utilized Cloudflare Workers for C2 communications.[4] |
| Enterprise | T1083 | File and Directory Discovery | |
| Enterprise | T1090.001 | Internal ProxySub-technique | |
| Enterprise | T1059.004 | Unix ShellSub-technique | BRICKSTORM has executed shell commands using `/bin/sh`.[5] |
| Enterprise | T1071.004 | DNSSub-technique | |
| Enterprise | T1489 | Service Stop | BRICKSTORM has terminated an existing process to ensure that its own new process can execute.[1] |
| Enterprise | T1005 | Data from Local System | BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file.[1] |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | f0c46d22e753… | ||
| 19.1 | 1.0 | Older bundle | f0c46d22e753… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]CISA BRICKSTORM UNC5221 AR25-338A February 2026
DHS/CISA. (2026, February 11). AR25-338A: BRICKSTORM Backdoor. Retrieved April 16, 2026.
Open source URL - [2]Picus Security BRICKSTORM UNC5221 October 2025
Huseyin Can Yuceel. (2025, October 1). BRICKSTORM Malware: UNC5221 Targets Tech and Legal Sectors in the United States. Retrieved April 16, 2026.
Open source URL - [3]Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025
Resecurity Threat Intelligence & Incident Analysis. (2025, October 22). F5 BIG-IP Source Code Leak Tied to State-Linked Campaigns Using BRICKSTORM Backdoor. Retrieved April 16, 2026.
Open source URL - [4]Google BRICKSTORM September 2025
Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen. (2025, September 24). Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors. Retrieved April 16, 2026.
Open source URL - [5]Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024
Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies. Retrieved April 16, 2026.
Open source URL - [6]Cloudflare 2026 Threat Report New Threat Actors March 2026
Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.
Open source URL - [7]CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025
CrowdStrike. (2025, December 4). Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary. Retrieved April 16, 2026.
Open source URL - [8]Dragos SYLVANITE MuddyWater Electrum March 2026
Dragos. (2026, March 24). Dragos 2026 OT Cybersecurity Report: Year in Review, O&G and Petrochemicals Focus. Retrieved April 17, 2026.
Open source URL - [9]NVISO BRICKSTORM April 2025
NVISO Incident Response. (2025, April 1). BRICKSTORM Backdoor Analysis: A Persistent Espionage Threat to European Industries. Retrieved April 16, 2026.
Open source URL - [10]Google BRICKSTORM GRIMBOLT UNC5221 UNC6201 February 2026
Peter Ukhanov, Daniel Sislo, Nick Harbour, John Scarbrough, Fernando Tomlinson Jr., Rich Reece. (2026, February 17). From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day. Retrieved April 16, 2026.
Open source URL - [11]mitre-attackS9015Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
