China-linked attackers exploited a maximum-severity hardcoded-credential bug in Dell RecoverPoint for Virtual Machines as a zero-day since at least mid-2024. It's all part of a long-running effort to backdoor infected machines for long-term access, according to Google's Mandiant incident response team. The US government and Google first warned about this campaign last year after detecting Brickstorm backdoors in dozens of critical US networks. Dell disclosed and patched the critical flaw (CVE-2026-22769) on Tuesday – but noted that miscreants had found and exploited the bug before it issued a fix. "We have received a report of limited active exploitation of this vulnerability," a Dell spokesperson told The Register. "Customers are urged to immediately implement one of the remediations detailed" in the advisory. According to Mandiant and the Google Threat Intelligence Group, which also published a security alert on Tuesday about the Dell zero-day, the suspected PRC-linked intruders exploited CVE-2026-22769 to deploy malware including Brickstorm and a separate backdoor tracked as Grimbolt, and in some cases replaced older Brickstorm binaries with Grimbolt, while also creating “Ghost NICs” on virtual machines to enable stealthy network pivoting. "Analysis of incident response engagements revealed that UNC6201, a suspected PRC-nexus threat cluster, has exploited this flaw since at least mid-2024 to move laterally, maintain persistent access, and deploy malware including Slaystyle...
Dell 0-day exploited by suspected Chinese snoops since 2024
The Register
·Jessica Lyons
·Published Feb 18, 2026
·Updated
Affected Software
1 affected component
Dell RecoverPoint for Virtual Machines=All versions, <unknown
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in Dell RecoverPoint for Virtual Machines that has been exploited by suspected Chinese attackers since mid-2024.
2
What security implications are discussed?
The vulnerability allows attackers to backdoor infected machines, posing significant risks to data security and system integrity.
3
What products or software are affected?
The affected software is Dell RecoverPoint for Virtual Machines, with all versions being vulnerable.
4
Who is believed to be behind the attacks?
The attacks are suspected to be carried out by China-linked threat actors.
5
Since when has this vulnerability been actively exploited?
The vulnerability has reportedly been exploited since at least mid-2024.