Chinese cyberspies maintained long-term access to critical networks – sometimes for years – and used this access to infect computers with malware and steal data, according to Thursday warnings from government agencies and private security firms. PRC-backed goons infected at least eight government services and IT organizations with Brickstorm backdoors, according to a joint security alert from the US Cybersecurity and Infrastructure Security Agency, the US National Security Agency, and the Canadian Cyber Security Centre. However, "it's a logical conclusion to assume that there are additional victims out there until we have not yet had the opportunity to communicate with," CISA's Nick Andersen, executive assistant director for cybersecurity, told reporters on Thursday, describing Brickstorm as a "terribly sophisticated piece of malware." The backdoor works across Linux, VMware, and Windows environments, and while Andersen declined to attribute the malware infections to a specific People's Republic of China cyber group, he said it illustrates the threat PRC crews pose to US critical infrastructure. "State-sponsored actors are not just infiltrating networks," Andersen said. "They're embedding themselves to enable long term access, disruption, and potential sabotage." In one incident that CISA responded to, the PRC goons gained access to the organization's internal network in April 2024, uploaded Brickstorm to an internal VMware vCenter server, and used the backdoor for persistent...
PRC spies Brickstromed their way into critical US networks
The Register
·Jessica Lyons
·Published Dec 4, 2025
·Updated
Affected Software
4 affected components
N/A Brickstorm
N/A Linux
N/A VMware
N/A Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how Chinese cyberspies gained long-term access to critical US networks through a method called 'Brickstorm' and subsequently infecting systems with malware.
2
What security implications are discussed?
The article highlights the risk of espionage and data theft due to prolonged access by adversaries into sensitive networks.
3
What products or software are affected?
The affected products include Brickstorm, Linux, VMware, and Windows systems.
4
What organizations issued warnings regarding the security breaches?
Warnings were issued by government agencies and private security firms regarding the breaches by Chinese cyberspies.
5
What techniques did the attackers use to maintain access to the networks?
The attackers utilized the 'Brickstorm' technique to infiltrate and maintain long-term access to critical networks.