Historical intelligence backfill. This assessment covers reporting originally published on 2025-09-24 and was added to the RWP archive on 2026-09-07.

Daily Top · Nation-State

BRICKSTORM lived 393 days on appliances with no EDR — legal and SaaS were the point

GTIG 24 September 2025 — UNC5221 and related China-nexus clusters put a Go backdoor on vCenter and other Linux/BSD boxes. Average dwell 393 days. Downstream zero-day research is the assessed prize, not a smash-and-grab.

RWP Ventures · 2026-09-07 · event 2025-03-01 · 2 min read · priority 8.6

Bottom line up front

CONFIRMED On 24 September 2025 Google Threat Intelligence Group published that BRICKSTORM — a Go backdoor with SOCKS proxy, file ops, and WebSocket C2, often masquerading as vCenter vami-http / updatemgr — was the persistence tool in Mandiant cases since March 2025. Verticals named: U.S. legal services, SaaS, BPOs, technology. Attribution: UNC5221 and closely related suspected China-nexus clusters that also zero-day network appliances. Average undetected dwell 393 days. DoH (Quad9/Google/Cloudflare) hides lookup of actor infrastructure.

ASSESSED Legal and SaaS are not random. Client files plus vendor source code is how you both spy and feed the next edge-device 0-day. GTIG's later 2025 zero-day review said the same in plainer language. CrowdStrike tracks overlapping vCenter work as WARP PANDA with Junction/GuestConduit on ESXi — overlap, not a forced merge.

This is not an OT process incident. It is hypervisor and appliance espionage that will later show up as someone else's CVE.

What happened

Mandiant found BRICKSTORM on Linux and BSD appliances that do not run EDR. Initial access is often an edge 0-day with logs already rotated. Lateral movement generates almost no security telemetry. SOCKS on the appliance is the jump.

Why it matters

If your vCenter, ESXi, or “smart” Linux appliance is the identity plane for the rest of the estate, 393 days is a full fiscal year of silent collection.

What is confirmed vs not

CONFIRMED GTIG/Mandiant campaign write-up, dwell statistic, verticals, Go/SOCKS/DoH behaviors.

REPORTED CrowdStrike WARP PANDA as a named overlap.

UNKNOWN a public victim list from the 24 September post.

What defenders should do

  1. Treat vCenter/ESXi as Tier-0. Hunt unexpected vami-http binaries and DoH from appliances.
  2. Assume edge-device 0-days; shorten log retention is not a defense.
  3. Legal/SaaS: the data is the product. Extortion and PRC collection can share a foothold.

RWP assessment

Confidence: High on GTIG's campaign facts. Do not wait for a Windows EDR alert that will never fire on the box that matters.

Historical intelligence backfill. This assessment covers reporting originally published on 2025-09-24 and was added to the RWP archive on 2026-09-07.

Sources

  1. GTIG — Another BRICKSTORM stealthy backdoor
  2. CrowdStrike — WARP PANDA BRICKSTORM on vCenter
  3. GTIG — 2025 zero-days in review (BRICKSTORM IP theft)