/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

US and Canadian agencies warn that Chinese hackers are using Brickstorm malware to penetrate and maintain backdoor access to unnamed government and IT entities

Chinese-linked hackers used sophisticated malware to penetrate and maintain long-term access to unnamed government …

Reuters A.J. Vicens

Context & Ripple Effects

The warning extends the known use of Brickstorm beyond the reported long-running intrusion at F5, where sources said China-backed actors used the malware to remain in the network and steal source code. It also fits a record of China-linked activity against US communications networks, including the Salt Typhoon campaign targeting US ISPs.

Earlier advisories described exploitation of known flaws to monitor network traffic, while Microsoft reported compromises of US critical-infrastructure organizations. The new joint US-Canadian alert matters because it centers persistence: access that can survive long after initial entry is detected.

First-order effects

  • Government and IT defenders now have a shared warning that Brickstorm may be used to establish and retain covert access, raising the urgency of hunting for persistence rather than only blocking initial intrusion paths.
  • The alert gives US and Canadian agencies a common basis for incident-response coordination around suspected China-linked activity affecting unnamed organizations.

Second-order effects

  • IT suppliers and service providers may face more customer pressure to demonstrate monitoring of network devices and privileged access, reflecting prior warnings that BlackTech breached network devices to install backdoors.
  • Organizations reviewing Brickstorm exposure are likely to broaden investigations to older access and connected systems, increasing demand for forensic and identity-focused security work rather than point-in-time vulnerability remediation alone.

Third-order effects

  • If repeated across targets, long-dwell backdoor campaigns would make resilience depend increasingly on continuous detection, credential control, and recovery capabilities—not merely patching known vulnerabilities.
  • The pattern points to cyber-defense cooperation becoming more operationally integrated across allied governments and critical IT ecosystems, though the alert alone does not establish how widespread Brickstorm use is.

The trend: State-linked intrusion campaigns are shifting the defensive focus from preventing entry alone to finding and removing durable access across interconnected infrastructure.

Discussion

  • @cisacyber @cisacyber on x
    🚨 PRC state-sponsored actors are actively using BRICKSTORM malware to establish long-term persistence, specifically targeting VMware vSphere platforms. Act now: hunt for intrusions and apply mitigations detailed in our 🆕 Malware Analysis Report: 🔗 https://www.cisa.gov/... [video]