{"id":9382,"date":"2025-12-21T10:03:48","date_gmt":"2025-12-21T10:03:48","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/21\/cisa-releases-new-indicators-of-compromise-tied-to-brickstorm-malware\/"},"modified":"2025-12-21T10:03:48","modified_gmt":"2025-12-21T10:03:48","slug":"cisa-releases-new-indicators-of-compromise-tied-to-brickstorm-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/21\/cisa-releases-new-indicators-of-compromise-tied-to-brickstorm-malware\/","title":{"rendered":"CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware"},"content":{"rendered":"<p>    CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA), along with the National Security Agency (NSA) and Canadian Centre for Cyber Security (Cyber Centre), has released updated indicators of compromise (IOCs) and detection signatures for BRICKSTORM malware. <\/p>\n<p>The latest update, published on December 19, 2025, includes an analysis of three additional malware samples, bringing the total to 11 analyzed variants.<\/p>\n<p>BRICKSTORM is a sophisticated <a href=\"https:\/\/cybersecuritynews.com\/techniques-to-detect-outlook-notdoor\/\" target=\"_blank\" rel=\"noreferrer noopener\">backdoor malware<\/a> attributed to People\u2019s Republic of China (PRC) state-sponsored cyber actors, who have been using it to maintain long-term persistence on compromised systems. <\/p>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"870\" height=\"429\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-33.png?resize=870%2C429&#038;ssl=1\" alt=\"PRC State-Sponsored Cyber Actors\u2019 Lateral Movement\" class=\"wp-image-137239\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-33.png 870w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-33-300x148.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-33-768x379.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-33-852x420.png 852w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-33-696x343.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-33-324x160.png 324w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-33-150x74.png 150w\" sizes=\"(max-width: 870px) 100vw, 870px\"><figcaption class=\"wp-element-caption\"><em>PRC State-Sponsored Cyber Actors\u2019 Lateral Movement<\/em><\/figcaption><\/figure>\n<p>The malware primarily targets organizations in the\u00a0Government Services and Facilities\u00a0and\u00a0Information Technology sectors, with particular focus on VMware vSphere environments, including VMware vCenter servers and VMware ESXi platforms.<\/p>\n<p>The malware represents a significant threat due to its advanced capabilities. BRICKSTORM is custom-built using\u00a0Go or Rust programming languages\u00a0and operates as an Executable and Linkable Format (ELF) backdoor. <\/p>\n<p>The eight samples initially analyzed were Go-based, while two of the three newly added samples in the December 19 update are Rust-based, demonstrating the threat actors\u2019 evolving techniques.<\/p>\n<p>According to the <a href=\"https:\/\/www.cisa.gov\/news-events\/analysis-reports\/ar25-338a\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CISA joint advisory<\/a>, BRICKSTORM provides cyber actors with comprehensive system control. <\/p>\n<p>The malware uses\u00a0multiple layers of encryption, including HTTPS, WebSockets, and nested Transport Layer Security (TLS), to conceal communications with command-and-control servers. <\/p>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"994\" height=\"706\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-32.png?resize=994%2C706&#038;ssl=1\" alt=\"BRICKSTORM Operational Flow\" class=\"wp-image-137238\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-32.png 994w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-32-300x213.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-32-768x545.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-32-591x420.png 591w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-32-696x494.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-32-100x70.png 100w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/12\/image-32-150x107.png 150w\" sizes=\"(max-width: 994px) 100vw, 994px\"><figcaption class=\"wp-element-caption\"><em>BRICKSTORM Operational Flow<\/em><\/figcaption><\/figure>\n<p>It also employs DNS-over-HTTPS (DoH) and mimics legitimate web server functionality to blend malicious traffic with regular network activity.<\/p>\n<p>CISA conducted an incident response engagement for one victim organization in which PRC actors gained persistent access to the internal network in April 2024. The attackers uploaded BRICKSTORM to an internal <a href=\"https:\/\/cybersecuritynews.com\/vmware-vcenter-and-nsx-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">VMware vCenter<\/a> server. <\/p>\n<p>They compromised two domain controllers and an Active Directory Federation Services (ADFS) server, successfully exporting cryptographic keys. The malware provided\u00a0persistent access from at least April 2024 through September 2025.<\/p>\n<p>Once deployed, BRICKSTORM grants threat actors interactive shell access, allowing them to browse, upload, download, create, delete, and manipulate files on compromised systems. <\/p>\n<p>Some variants also function as\u00a0SOCKS proxies, facilitating lateral movement across networks and enabling compromise of additional systems.<\/p>\n<p>CISA, NSA, and Cyber Centre strongly urge organizations to utilize the released IOCs and detection signatures, including <a href=\"https:\/\/cybersecuritynews.com\/how-to-use-yara-rules-to-identify-financial-sector-targeted-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">YARA <\/a>and Sigma rules, to identify BRICKSTORM samples within their environments. <\/p>\n<p>If BRICKSTORM or related activity is detected, organizations should immediately report incidents to CISA, Cyber Centre, or appropriate authorities.<\/p>\n<p>The agencies have made downloadable copies of IOCs available in STIX format, along with Sigma detection rules in YAML format. Organizations can access these resources through CISA\u2019s official website to enhance their defensive capabilities against this persistent threat.<\/p>\n<p>This advisory underscores the ongoing sophistication of state-sponsored cyber operations and the critical need for organizations, particularly those in government and critical infrastructure sectors, to implement robust detection and response capabilities.<\/p>\n<p class=\"has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-indicators-of-compromise-tied-to-brickstorm-malware\/\">CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-indicators-of-compromise-tied-to-brickstorm-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware The Cybersecurity and Infrastructure Security Agency (CISA), along with the National Security Agency (NSA) and Canadian Centre for Cyber Security (Cyber Centre), has released updated indicators of compromise (IOCs) and detection signatures for BRICKSTORM malware. The latest update, published on December 19, 2025, includes an [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258],"tags":[130],"class_list":["post-9382","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9382"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9382"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9382\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}