The Containment Era is here. →Explore

Executive Summary

In 2025, a highly sophisticated cyberespionage campaign attributed to a suspected Chinese advanced persistent threat (APT), utilizing malware later dubbed 'Brickstorm,' successfully infiltrated multiple US legal services and tech supply chain organizations. The attackers leveraged undisclosed zero-day vulnerabilities to gain initial access, maintain exceptional stealth with average dwell times of over 400 days, and move laterally into downstream customers. Their campaign targeted proprietary source code and sensitive trade/national security intelligence, making detection challenging through advanced cleanup techniques and non-overlapping infrastructure.

This incident is particularly significant as it represents a new echelon of APT supply chain intrusions, echoing a rise in strategic, multi-year campaigns focusing on SaaS and cloud intermediaries. It highlights the growing need for robust east-west visibility, zero trust segmentation, and supply chain security amid evolving TTPs that routinely outpace traditional detection and response capabilities.

Why This Matters Now

The Brickstorm campaign demonstrates that supply chain and SaaS providers are increasingly prioritized by highly resourced threat actors aiming for maximum downstream access. Its persistence, stealth, and use of novel zero-days raise urgent concerns about unmonitored infrastructure and the real risk of undetected compromise lasting years. Organizations must act quickly to review east-west security controls and cloud visibility.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Inadequate east-west traffic monitoring, insufficient segmentation for SaaS/cloud infrastructure, and lack of zero trust controls enabled attackers’ prolonged, undetected presence.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Cloud Network Security Framework (CNSF) controls like Zero Trust Segmentation, East-West Traffic Security, Egress Policy, inline IPS, and anomaly detection could have significantly restricted attacker movement, hastened detection, and stopped data exfiltration—even in environments targeted by Brickstorm’s stealthy cloud footholds.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline posture controls and distributed policy enforcement hinder initial exploit success.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Centralized policy and monitoring detect abnormal privilege escalations.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Segmentation restricts unauthorized internal communications and east-west movement.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Known bad payloads and C2 signatures are detected and blocked.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Outbound data exfiltration attempts are prevented or logged.

Impact (Mitigations)

Anomalous behavior and destructive actions are rapidly surfaced and contained.

Impact at a Glance

Affected Business Functions

  • Network Security
  • Remote Access Services
  • Data Protection
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive corporate data, including intellectual property and confidential communications, due to unauthorized access facilitated by the BRICKSTORM malware.

Recommended Actions

  • Enforce zero trust segmentation and granular identity-based policies across internal cloud and hybrid workloads.
  • Implement robust egress controls—including FQDN filtering and outbound monitoring—to arrest data exfiltration attempts.
  • Deploy continuous east-west traffic inspection and inline IPS to detect lateral movement and covert C2.
  • Enhance multicloud and SaaS environment visibility to rapidly surface abnormal privilege escalations or policy drift.
  • Operationalize anomaly detection and automated incident response to quickly detect and contain advanced persistent threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image