The Containment Era is here. →Explore

Executive Summary

In 2024, U.S. and Canadian cybersecurity authorities, together with threat analysts from Google and CrowdStrike, disclosed an extensive, ongoing cyber-espionage campaign attributed to China-linked state actors known as Warp Panda and UNC5221. Utilizing the advanced Brickstorm malware, attackers achieved undetected persistence within critical infrastructure and government agency networks for an average of over a year, beginning as early as 2022. Brickstorm, targeting VMware vSphere and Windows environments, enabled stealthy lateral movement, automated reinfection, and the theft of sensitive identity and configuration data. The campaign exploited cloud misconfigurations, edge device vulnerabilities, and under-monitored zones, impacting dozens of U.S. organizations and associated downstream victims.

This incident reflects the continued evolution of state-sponsored Chinese cyber-operations. Its strategic targeting, tradecraft sophistication, and stealth tactics represent persistent threats for both government and private sector organizations managing hybrid or multi-cloud environments.

Why This Matters Now

Brickstorm exemplifies how state-sponsored espionage campaigns exploit security blind spots, including edge devices and cloud platforms. The campaign’s scope and long dwell time highlight systemic detection and response gaps, underscoring the urgency for organizations to strengthen visibility, segmentation, and incident response—especially as geopolitical tensions drive increasingly aggressive nation-state cyber activity.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The campaign highlighted shortcomings in monitoring internal and edge environments, insufficient segmentation, lack of encrypted traffic for sensitive data, and inadequate governance across hybrid/multi-cloud networks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix CNSF controls like zero trust segmentation, east-west traffic security, egress policy enforcement, and centralized threat detection would have significantly constricted attacker movement, rapidly surfacing anomalous behaviors, and limiting persistence and data theft within this campaign.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocks initial unauthorized ingress traffic targeting perimeter vulnerabilities.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Prevents lateral privilege escalation by limiting access between identities and critical assets.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocks or alerts on suspicious internal (east-west) lateral movements.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Realtime alerting and disruption of suspicious C2 patterns and covert traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents unauthorized outbound data flows and detects exfiltration events.

Impact (Mitigations)

Reduces dwell time and long-term persistence via unified monitoring and rapid response.

Impact at a Glance

Affected Business Functions

  • IT Operations
  • Data Management
  • Legal Services
Operational Disruption

Estimated downtime: 30 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive configuration data, identity metadata, documents, and emails related to strategic interests.

Recommended Actions

  • Implement zero trust segmentation and microsegmentation to restrict lateral movement and contain breaches.
  • Enforce comprehensive egress filtering and encrypted traffic monitoring to identify and block data exfiltration.
  • Deploy advanced threat detection, baselining, and real-time anomaly response across multi-cloud and hybrid networks.
  • Harden identity and privilege access management with policy enforcement and least privilege controls.
  • Ensure centralized, continuous visibility and policy management for all cloud and edge assets to rapidly surface persistent threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image