Suspected Chinese hackers have used the Brickstorm malware in long-term persistence espionage operations against U.S. organizations in the technology and legal sectors. Brickstorm is a Go-based backdoor documented by Google in April 2024 following China-related intrusions that spawned from various edge devices and remained undetected in the victim environment for more than a year, on average. The malware served as a web server, file manipulation tool, dropper, SOCKS relay, and shell command execution tool. According to Google Threat Intelligence Group (GTIG), the attackers used Brickstorm to silently siphon data from their victims’ networks for an average dwell time of 393 days before being detected. The researchers confirmed compromised organizations in the legal and technology sectors, software-as-a-service (SaaS) providers, and also Business Process Outsourcers (BPOs). Google notes that compromising such entities could help a threat actor develop zero-day exploits and extend the attack to downstream victims, especially those not protected by endpoint detection and response (EDR) solutions. The researchers attributed these attacks to the UNC5221 activity cluster, notorious for exploiting Ivanti zero-days to attack government agencies with custom malware like Spawnant and Zipline. Due to the long dwell time on victim systems and UNC5221’s use of anti-forensics scripts to obscure the entry path, GTIG coulld not confidently determine the initial access vector, but the researc...
Google: Brickstone malware used to steal U.S. orgs' data for over a year
BleepingComputer
·Bill Toulas
·Published Sep 24, 2025
·Updated
Affected Software
1 affected component
Google Brickstorm
Frequently Asked Questions
1
What is Brickstorm malware?
Brickstorm is a Go-based backdoor malware used for espionage operations.
2
Which organizations were targeted by the Brickstorm malware?
Brickstorm primarily targeted U.S. organizations in the technology and legal sectors.
3
Who is suspected to be behind the Brickstorm malware attacks?
Suspected Chinese hackers are believed to have deployed the Brickstorm malware.
4
How long has Brickstorm malware been in use against U.S. organizations?
The Brickstorm malware has reportedly been used for over a year.
5
What type of security threat does Brickstorm represent?
Brickstorm represents a significant security threat due to its use in long-term persistence espionage campaigns.