惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
Webroot Blog
Webroot Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Threat Research - Cisco Blogs
V2EX - 技术
V2EX - 技术
L
LINUX DO - 热门话题
Google DeepMind News
Google DeepMind News
Recorded Future
Recorded Future
S
Schneier on Security
I
InfoQ
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
The GitHub Blog
The GitHub Blog
S
Security @ Cisco Blogs
O
OpenAI News
W
WeLiveSecurity
Vercel News
Vercel News
阮一峰的网络日志
阮一峰的网络日志
Simon Willison's Weblog
Simon Willison's Weblog
人人都是产品经理
人人都是产品经理
Cloudbric
Cloudbric
The Last Watchdog
The Last Watchdog
The Hacker News
The Hacker News
Google Online Security Blog
Google Online Security Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
NISL@THU
NISL@THU
T
Tailwind CSS Blog
V
Visual Studio Blog
PCI Perspectives
PCI Perspectives
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Jina AI
Jina AI
D
DataBreaches.Net
B
Blog RSS Feed
N
News and Events Feed by Topic
N
News and Events Feed by Topic
H
Heimdal Security Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
腾讯CDC
Latest news
Latest news
V
Vulnerabilities – Threatpost
Hacker News: Ask HN
Hacker News: Ask HN
WordPress大学
WordPress大学
V
V2EX
aimingoo的专栏
aimingoo的专栏
博客园 - 司徒正美
Apple Machine Learning Research
Apple Machine Learning Research
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Register - Security
The Register - Security
Help Net Security
Help Net Security

The Register - Security: Research

www.theregister.com Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine ChatGPT blindly trusts browser content, turning the page into a payload Russia-linked threat group put ChatGPT to work from lure to payload Kids can bypass some age checks with a drawn-on mustache What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia ORNL builds more sensitive GPS interference detector Researchers find sabotage malware that may predate Stuxnet Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus Anthropic, Google, Microsoft paid AI bug bounties – quietly Security reserchers tricked Apple Intelligence into cursing Don't open that WhatsApp message, Microsoft warns Security boffins harvest bumper crop of API keys from web Lightning-fast exploits mean patch fast, says Cisco Talos AI agents are 'gullible' and easy to turn into your minions Smooth criminals talking their way into cloud environments, Google says Snoops plant info-stealing malware on iPhones, Google warns Cybercrime up 245% since the start of the Iran war Rogue AI agents can work together to hack systems Fake applicants are sending security-killing malware AI agent hacked McKinsey chatbot for read-write access Kaspersky: No signs Coruna iPhone exploit kit made by US Perplexity Comet browser hole was exploitable via cal invite DEF CON hackers 'fed up with government,' Jake Braun says DEF CON hackers 'fed up with government,' Jake Braun says Ransomware payments cratered in 2025 – attacks did not Ransomware payments cratered in 2025 – attacks did not Claude's collaboration tools allowed remote code execution AI takes a swing at online anonymity Fake 'interview' repos lure Next.js devs into running secret-stealing malware Threat intelligence supply chain is full of weak links AI agents abound, unbound by rules or safety disclosures RAT disguised as an RMM costs crims $300 a month Android malware taps Gemini to navigate infected devices Posting AI caricatures on social media is bad for security Payroll pirates conned the help desk, stole employee’s pay Microsoft boffins show LLM safety can be trained away For the price of Netflix, crooks can rent AI crime ops For the price of Netflix, crooks can rent AI crime ops Fast Pair, loose security: Bluetooth accessories open to silent hijack Fast Pair flaw exposes Bluetooth devices to hijacking A simple CodeBuild flaw put every AWS environment at risk A simple CodeBuild flaw put every AWS environment at risk DeadLock ransomware uses smart contracts to evade defenders Python libraries in AI/ML models can be poisoned w metadata OpenAI patches déjà vu prompt injection vuln in ChatGPT Fake Windows BSODs check in at Europe's hotels to con staff into running malware Hotel staff tricked into installing malware by bogus BSODs Your car’s web browser may be on the road to cyber ruin China's Ink Dragon hides out in European government networks Browser 'privacy' extensions have eye on your AI, log all your chats NCSC finds cyber deception tools work, if deployed right 10K Docker images spray live cloud creds across the internet 'Botnets in physical form' are top humanoid robot risk 'Botnets in physical form' are top humanoid robot risk Apache warns of 10.0-rated flaw in Tika metadata toolkit Novel clickjacking attack relies on CSS and SVG 'Exploitation is imminent' of max-severity React bug Swiss government bans SaaS and cloud for sensitive info Scattered Lapsus$ Hunters stress testing Zendesk weak spots HashJack attack shows AI browsers can be fooled with '#' New ClickFix attacks use fake Windows Updates to swipe creds Years-old bugs in open source took out major clouds at risk LLM-generated malware improving, but not operational (yet) 3.5B WhatsApp users' info scooped through enumeration flaw 3.5B WhatsApp users' info scooped through enumeration flaw 50k more ASUS routers pwned by evolving Beijing-linked op Overconfidence is the new zero-day as teams stumble through cyber simulations LLM side-channel attack could allow snoops to guess topic Landfall spyware used in 0-day attacks on Samsung phones MIT Sloan shelves paper about AI-driven ransomware Security hole slams Chromium browsers - no fix yet OpenAI Atlas Browser tripped up by malformed URLs Devs of VS Code extensions are leaking secrets en masse Chatbots that butter you up make you worse at conflict Tile trackers leak unencrypted Bluetooth data, say boffins Beijing's RedNovember hacked critical US, global orgs Lazarus RAT code resurfaces in North Korean IT-worker scams Deepfaked calls hit 44% of businesses in last year: Gartner Kaspersky: RevengeHotels returns with AI-coded malware Ruh-roh. DDR5 memory vulnerable to new Rowhammer attack HybridPetya ransomware dodges UEFI Secure Boot
Suspected Chinese spies broke into 'numerous' enterprises
Jessica Lyons Jessica Lyons · 2025-09-24 · via The Register - Security: Research

Unknown intruders – likely China-linked spies – have broken into "numerous" enterprise networks since March and deployed backdoors, providing access for their long-term IP and other sensitive data stealing missions, all the while remaining undetected on average for 393 days, according to Google Threat Intelligence.

In a paper published today, the threat hunters attribute these network intrusions to UNC5221 and other related suspected Chinese threat groups. UNC5221 has been abusing zero-days in buggy Ivanti gear since at least 2023.

Google notes that this UNC crew is separate from Silk Typhoon (aka Hafnium), believed to be behind the December break-in at the US Treasury Department

UNC in Google's threat-group naming taxonomy stands for "Uncategorized," as opposed to FIN (financially motivated) or APT (advanced persistent threat, which means government-backed). [Editor's note: read all about the various security companies' methods for naming cyber crews here... then go bang your head against the wall.]

Since March, Google's Mandiant Consulting and incident response team have responded to these UNC5221-related break-ins across legal services, Software as a Service (SaaS) providers, Business Process Outsourcers (BPOs), and technology companies. 

"The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims," Google Threat Intelligence wrote.

Don't count on your EDR detecting this BRICKSTORM

A big reason why the intruders are able to remain on victims' networks for so long before being detected is due to their use of backdoors – primarily BRICKSTORM – on appliances that do not support traditional endpoint detection and response (EDR) tools. This means that victim orgs' security teams aren't receiving any EDR alerts about suspicious activities.

Because of this, and to help organizations hunt for BRICKSTORM activity, Mandiant made available a free, downloadable scanner to run on *nix-based appliances and other systems without requiring YARA to be installed. It works by searching for a combination of strings and hex patterns unique to the backdoor.

And while Google declined to specify how many BRICKSTORM-activity victims it has identified since March, "the important thing to focus on is this group is scaling their capabilities," Mandiant Consulting Chief Technology Officer Charles Carmakal told The Register

We have no doubt companies will use this tool and find active or historic compromises

"As more companies scan their systems, we anticipate we'll be hearing about this campaign for the next one to two years," he said. "We have no doubt companies will use this tool and find active or historic compromises."

In at least one case, the suspected Chinese data thieves gained initial access by exploiting a zero-day vulnerability in an Ivanti Connect Secure edge device. Google declined to say which Ivanti zero-day the miscreants abused, but pointed to an earlier report about UNC5221 poking holes in CVE-2023-46805 and CVE-2024-21887 as early as December 2023, and "widespread exploitation" after Ivanti disclosed those two vulnerabilities in January 2024.

VMware, credentials, Microsoft inboxes among the targets

Once the attackers break in, they deploy backdoors to maintain persistent access, and the one they use most is BRICKSTORM. The malware, written in Go, includes SOCKS proxy functionality. And while there is evidence of a Windows BRICKSTORM variant, Mandiant's responders haven't seen this firsthand, but they have found the backdoor on Linux and BSD-based appliances from multiple manufacturers.

Plus, UNC5221, the threat hunters note, consistently targets VMware vCenter and ESXi hosts, and "in multiple cases, the threat actor deployed BRICKSTORM to a network appliance prior to pivoting to VMware systems." In these instances, the intruders used valid credentials – likely stolen by the malware running on the network appliances – to move laterally to a vCenter server in the victims' environments.

Based on malware samples recovered from various victim orgs, UNC5221 also appears to have modified BRICKSTORM making it even more difficult to detect. Some, we're told, were obfuscated using Garble, some use a new version of the custom wssoft library, and at least one had a "delay" timer built-in.

This timer waited for a hard-coded future date before beginning to beacon to the configured command and control (C2) domain. "Notably, this backdoor was deployed on an internal vCenter server after the victim organization had begun their incident response investigation, demonstrating that the threat actor was actively monitoring and capable of rapidly adapting their tactics to maintain persistence," the threat intelligence team wrote.

It's also worth noting that Mandiant didn't document any reuse of C2 domains – or even malware samples – and this makes traditional indicators of compromise (IOCs) largely obsolete.

In another investigation, the attackers installed a malicious Java Servlet filter for the Apache Tomcat server that runs the web interface for vCenter. This code is designed to run every time the web server receives an HTTP request. While installing a filter usually requires modifying a config file and then restarting the application, in this case the intruders used a custom dropper that made the modifications in memory, rather than requiring a restart – again adding to the stealthiness of the malware. 

Mandiant tracks this malicious filter as BRICKSTEAL, and says it is able to decode the HTTP Basic authentication header, which may contain a username and password. "Many organizations use Active Directory authentication for vCenter, which means BRICKSTEAL could capture those credentials," the report warns.

In many of these intrusions, the attackers also broke into email inboxes belonging to "key individuals." These include developers, system administrators, and others "involved in matters that align with PRC economic and espionage interests."

To access these inboxes, the snoops used Microsoft Entra ID Enterprise Applications with mail.read or full_access_as_app scopes, both of which allow the application to access mail in any mailbox. 

And to steal files from the victims' systems, UNC5221 used BRICKSTORM's SOCKS proxy feature to tunnel from their workstation and directly access systems and web applications.

Additionally, in "several" of these break-ins, the attackers removed the malware samples from the compromised systems. "In these cases, the presence of BRICKSTORM was observed by conducting forensic analysis of backup images that identified the BRICKSTORM malware in place," according to Google.

Hunting guidance

In addition to making available the scanner script, via GitHub, the Chocolate Factory also provides a lengthy section on hunting for BRICKSTORM activity on your network – while again noting that using IOCs aren't the most useful way to do that when the attacker doesn't reuse any C2 domains or malware samples. Instead, the threat intel analysts recommend a Tactics, Techniques, and Procedures (TTP)-based approach, deeming it a "necessity to detect patterns of attack that are unlikely to be detected by traditional signature-based defenses."

This nine-step checklist starts with creating (or updating) an asset inventory that includes edge devices and other appliances that are generally not covered by traditional security tool stacks including EDR products. 

Use this inventory of appliances and management IP addresses to hunt for indications of malware beaconing in network logs – such as appliances communicating with the public internet from a management IP address when they don't need to – as well as appliances accessing Windows systems and credentials and secrets, or enterprise apps accessing Microsoft 365 Exchange Online mailboxes, since all of these are hallmarks of this attacker.

Because UNC5221 regularly targets VMware vCenter and ESXi hosts, organizations should also hunt for cloning of sensitive virtual machines, creation of local vCenter and ESXi accounts, SSH enablement on the vSphere platform, and rogue VMs. The report provides detailed instructions on how to monitor for all of this, so be sure to check it out. Happy hunting. ®