Chinese cyberspies maintained long-term access to critical networks – sometimes for years – and used this access to infect computers with malware and steal data, according to Thursday warnings from government agencies and private security firms. PRC-backed goons infected at least eight government services and IT organizations with Brickstorm backdoors, according to a joint security alert from the US Cybersecurity and Infrastructure Security Agency, the US National Security Agency, and the Canadian Cyber Security Centre. However, "it's a logical conclusion to assume that there are additional victims out there until we have not yet had the opportunity to communicate with," CISA's Nick Andersen, executive assistant director for cybersecurity, told reporters on Thursday, describing Brickstorm as a "terribly sophisticated piece of malware." The backdoor works across Linux, VMware, and Windows environments, and while Andersen declined to attribute the malware infections to a specific People's Republic of China cyber group, he said it illustrates the threat PRC crews pose to US critical infrastructure. "State-sponsored actors are not just infiltrating networks," Andersen said. "They're embedding themselves to enable long term access, disruption, and potential sabotage." In one incident that CISA responded to, the PRC goons gained access to the organization's internal network in April 2024, uploaded Brickstorm to an internal VMware vCenter server, and used the backdoor for persistent...
PRC spies Brickstormed their way into critical US networks and remained hidden for years
The Register
·Jessica Lyons
·Published Dec 4, 2025
·Updated
Affected Software
3 affected components
Unknown Linux
Unknown VMware
Unknown Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how Chinese cyberspies have infiltrated critical US networks, remaining undetected for years while stealing data and deploying malware.
2
What security implications are discussed in the article?
The article highlights the risks of long-term access by foreign spies, posing threats to national security and critical infrastructure.
3
What products or software are affected by the attacks mentioned?
The affected software includes various versions of Linux, VMware, and Windows.
4
How did the attackers maintain access to the networks?
The attackers employed sophisticated tactics to avoid detection, allowing them to sustain their access for extended periods.
5
What actions are being taken in response to these threats?
Government agencies like CISA are issuing warnings and alerts to raise awareness and enhance cybersecurity defenses against such espionage tactics.