• News/
  • https://www.bleepingcomputer.com/news/security/google-brickstone-malware-used-to-steal-us-orgs-data-for-over-a-year/

Google: Brickstone malware used to steal U.S. orgs' data for over a year

BleepingComputer
·
Bill Toulas
·
Published Sep 24, 2025
·
Updated

Suspected Chinese hackers have used the Brickstorm malware in long-term persistence espionage operations against U.S. organizations in the technology and legal sectors. Brickstorm is a Go-based backdoor documented by Google in April 2024 following China-related intrusions that spawned from various edge devices and remained undetected in the victim environment for more than a year, on average. The malware served as a web server, file manipulation tool, dropper, SOCKS relay, and shell command execution tool. According to Google Threat Intelligence Group (GTIG), the attackers used Brickstorm to silently siphon data from their victims’ networks for an average dwell time of 393 days before being detected. The researchers confirmed compromised organizations in the legal and technology sectors, software-as-a-service (SaaS) providers, and also Business Process Outsourcers (BPOs). Google notes that compromising such entities could help a threat actor develop zero-day exploits and extend the attack to downstream victims, especially those not protected by endpoint detection and response (EDR) solutions. The researchers attributed these attacks to the UNC5221 activity cluster, notorious for exploiting Ivanti zero-days to attack government agencies with custom malware like Spawnant and Zipline. Due to the long dwell time on victim systems and UNC5221’s use of anti-forensics scripts to obscure the entry path, GTIG coulld not confidently determine the initial access vector, but the researc...

Read full article

Affected Software

1 affected component
Google Brickstorm
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is Brickstorm malware?

Brickstorm is a Go-based backdoor malware used for espionage operations.

2

Which organizations were targeted by the Brickstorm malware?

Brickstorm primarily targeted U.S. organizations in the technology and legal sectors.

3

Who is suspected to be behind the Brickstorm malware attacks?

Suspected Chinese hackers are believed to have deployed the Brickstorm malware.

4

How long has Brickstorm malware been in use against U.S. organizations?

The Brickstorm malware has reportedly been used for over a year.

5

What type of security threat does Brickstorm represent?

Brickstorm represents a significant security threat due to its use in long-term persistence espionage campaigns.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203