• News/
  • https://www.theregister.com/2026/02/18/dell_0day_brickstorm_campaign/

Dell 0-day exploited by suspected Chinese snoops since 2024

The Register
·
Jessica Lyons
·
Published Feb 18, 2026
·
Updated

China-linked attackers exploited a maximum-severity hardcoded-credential bug in Dell RecoverPoint for Virtual Machines as a zero-day since at least mid-2024. It's all part of a long-running effort to backdoor infected machines for long-term access, according to Google's Mandiant incident response team. The US government and Google first warned about this campaign last year after detecting Brickstorm backdoors in dozens of critical US networks. Dell disclosed and patched the critical flaw (CVE-2026-22769) on Tuesday – but noted that miscreants had found and exploited the bug before it issued a fix. "We have received a report of limited active exploitation of this vulnerability," a Dell spokesperson told The Register. "Customers are urged to immediately implement one of the remediations detailed" in the advisory. According to Mandiant and the Google Threat Intelligence Group, which also published a security alert on Tuesday about the Dell zero-day, the suspected PRC-linked intruders exploited CVE-2026-22769 to deploy malware including Brickstorm and a separate backdoor tracked as Grimbolt, and in some cases replaced older Brickstorm binaries with Grimbolt, while also creating “Ghost NICs” on virtual machines to enable stealthy network pivoting. "Analysis of incident response engagements revealed that UNC6201, a suspected PRC-nexus threat cluster, has exploited this flaw since at least mid-2024 to move laterally, maintain persistent access, and deploy malware including Slaystyle...

Read full article

Affected Software

1 affected component
Dell RecoverPoint for Virtual Machines=All versions, <unknown

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in Dell RecoverPoint for Virtual Machines that has been exploited by suspected Chinese attackers since mid-2024.

2

What security implications are discussed?

The vulnerability allows attackers to backdoor infected machines, posing significant risks to data security and system integrity.

3

What products or software are affected?

The affected software is Dell RecoverPoint for Virtual Machines, with all versions being vulnerable.

4

Who is believed to be behind the attacks?

The attacks are suspected to be carried out by China-linked threat actors.

5

Since when has this vulnerability been actively exploited?

The vulnerability has reportedly been exploited since at least mid-2024.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203