Executive Summary
In 2025, a highly sophisticated cyberespionage campaign attributed to a suspected Chinese advanced persistent threat (APT), utilizing malware later dubbed 'Brickstorm,' successfully infiltrated multiple US legal services and tech supply chain organizations. The attackers leveraged undisclosed zero-day vulnerabilities to gain initial access, maintain exceptional stealth with average dwell times of over 400 days, and move laterally into downstream customers. Their campaign targeted proprietary source code and sensitive trade/national security intelligence, making detection challenging through advanced cleanup techniques and non-overlapping infrastructure.
This incident is particularly significant as it represents a new echelon of APT supply chain intrusions, echoing a rise in strategic, multi-year campaigns focusing on SaaS and cloud intermediaries. It highlights the growing need for robust east-west visibility, zero trust segmentation, and supply chain security amid evolving TTPs that routinely outpace traditional detection and response capabilities.
Why This Matters Now
The Brickstorm campaign demonstrates that supply chain and SaaS providers are increasingly prioritized by highly resourced threat actors aiming for maximum downstream access. Its persistence, stealth, and use of novel zero-days raise urgent concerns about unmonitored infrastructure and the real risk of undetected compromise lasting years. Organizations must act quickly to review east-west security controls and cloud visibility.
Attack Path Analysis
The Brickstorm actors gained initial access using zero-day exploits, especially targeting systems lacking endpoint detection such as VMware vCenter and ESXi. Following access, the threat actors escalated privileges to gain broader control and persisted stealthily, often obscuring or cleaning up their tracks. They moved laterally across hybrid cloud and SaaS environments, exploiting privileged access to infiltrate downstream customers and internal networks. Command and Control was maintained via covert channels and obfuscated indicators, evading detection through dynamic infrastructure and frequent hash changes. Data was exfiltrated selectively, focusing on sensitive emails and intellectual property using encrypted or hidden outbound channels. The campaign's impact centers on long-term intelligence gathering, supply chain risk preparation, and future exploitation through the stolen source code and sensitive information.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited zero-day vulnerabilities and weak security posture on unmonitored cloud workloads (e.g., VMware vCenter, ESXi) to establish initial access without triggering typical endpoint defenses.
Related CVEs
CVE-2025-22457
CVSS 9A stack-based buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways allows remote unauthenticated attackers to execute arbitrary code, potentially leading to full system compromise.
Affected Products:
Ivanti Connect Secure – < 22.7R2.6
Ivanti Policy Secure – < 22.7R1.4
Ivanti ZTA Gateways – < 22.8R2.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Obtain Capabilities: Vulnerabilities
Valid Accounts
Impair Defenses: Disable or Modify Tools
Indicator Removal: File Deletion
Data from Local System
Automated Exfiltration
Data from Information Repositories
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Implement Automated Audit Trails
Control ID: 10.1.2
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.5
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA Zero Trust Maturity Model 2.0 – Comprehensive Visibility into Assets and Activities
Control ID: Visibility and Analytics
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO/IEC 27001:2022 – Event Logging
Control ID: A.12.4.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Legal Services
Primary APT targets face 400-day dwell times with email surveillance, IP theft, and zero-day exploitation requiring enhanced segmentation and encrypted traffic controls.
Computer/Network Security
Security service providers targeted for source code theft to develop future zero-days, enabling downstream customer compromises through supply chain infiltration.
Information Technology/IT
VMware infrastructure exploitation and SaaS provider compromises demand multicloud visibility, east-west traffic security, and advanced threat detection capabilities.
Government Administration
National security intelligence collection through legal and tech sector pivoting requires zero trust segmentation and enhanced anomaly detection responses.
Sources
- Brickstorm malware powering ‘next-level’ Chinese cyberespionage campaignhttps://cyberscoop.com/chinese-cyberespionage-campaign-brickstorm-mandiant-google/Verified
- CVE-2025-22457https://nvd.nist.gov/vuln/detail/CVE-2025-22457Verified
- CISA flags Ivanti VPN Flaw amid ongoing espionage attackshttps://hipaatimes.com/cisa-flags-ivanti-vpn-flaw-amid-ongoing-espionage-attacksVerified
- China-Linked Threat Group Exploits Ivanti Bughttps://www.darkreading.com/vulnerabilities-threats/china-linked-threat-group-exploits-ivanti-bug/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Cloud Network Security Framework (CNSF) controls like Zero Trust Segmentation, East-West Traffic Security, Egress Policy, inline IPS, and anomaly detection could have significantly restricted attacker movement, hastened detection, and stopped data exfiltration—even in environments targeted by Brickstorm’s stealthy cloud footholds.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline posture controls and distributed policy enforcement hinder initial exploit success.
Control: Multicloud Visibility & Control
Mitigation: Centralized policy and monitoring detect abnormal privilege escalations.
Control: Zero Trust Segmentation
Mitigation: Segmentation restricts unauthorized internal communications and east-west movement.
Control: Inline IPS (Suricata)
Mitigation: Known bad payloads and C2 signatures are detected and blocked.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data exfiltration attempts are prevented or logged.
Anomalous behavior and destructive actions are rapidly surfaced and contained.
Impact at a Glance
Affected Business Functions
- Network Security
- Remote Access Services
- Data Protection
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive corporate data, including intellectual property and confidential communications, due to unauthorized access facilitated by the BRICKSTORM malware.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and granular identity-based policies across internal cloud and hybrid workloads.
- • Implement robust egress controls—including FQDN filtering and outbound monitoring—to arrest data exfiltration attempts.
- • Deploy continuous east-west traffic inspection and inline IPS to detect lateral movement and covert C2.
- • Enhance multicloud and SaaS environment visibility to rapidly surface abnormal privilege escalations or policy drift.
- • Operationalize anomaly detection and automated incident response to quickly detect and contain advanced persistent threats.



