• News/
  • https://www.theregister.com/2025/12/04/prc_spies_brickstorm_cisa/

PRC spies Brickstormed their way into critical US networks and remained hidden for years

The Register
·
Jessica Lyons
·
Published Dec 4, 2025
·
Updated

Chinese cyberspies maintained long-term access to critical networks – sometimes for years – and used this access to infect computers with malware and steal data, according to Thursday warnings from government agencies and private security firms. PRC-backed goons infected at least eight government services and IT organizations with Brickstorm backdoors, according to a joint security alert from the US Cybersecurity and Infrastructure Security Agency, the US National Security Agency, and the Canadian Cyber Security Centre. However, "it's a logical conclusion to assume that there are additional victims out there until we have not yet had the opportunity to communicate with," CISA's Nick Andersen, executive assistant director for cybersecurity, told reporters on Thursday, describing Brickstorm as a "terribly sophisticated piece of malware." The backdoor works across Linux, VMware, and Windows environments, and while Andersen declined to attribute the malware infections to a specific People's Republic of China cyber group, he said it illustrates the threat PRC crews pose to US critical infrastructure. "State-sponsored actors are not just infiltrating networks," Andersen said. "They're embedding themselves to enable long term access, disruption, and potential sabotage." In one incident that CISA responded to, the PRC goons gained access to the organization's internal network in April 2024, uploaded Brickstorm to an internal VMware vCenter server, and used the backdoor for persistent...

Read full article

Affected Software

3 affected components
Unknown Linux
Unknown VMware
Unknown Windows
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how Chinese cyberspies have infiltrated critical US networks, remaining undetected for years while stealing data and deploying malware.

2

What security implications are discussed in the article?

The article highlights the risks of long-term access by foreign spies, posing threats to national security and critical infrastructure.

3

What products or software are affected by the attacks mentioned?

The affected software includes various versions of Linux, VMware, and Windows.

4

How did the attackers maintain access to the networks?

The attackers employed sophisticated tactics to avoid detection, allowing them to sustain their access for extended periods.

5

What actions are being taken in response to these threats?

Government agencies like CISA are issuing warnings and alerts to raise awareness and enhance cybersecurity defenses against such espionage tactics.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203