Executive Summary
In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported that state-sponsored hackers affiliated with the People's Republic of China (PRC) utilized a newly identified backdoor dubbed BRICKSTORM to infiltrate and maintain long-term access within VMware vSphere and Windows environments of U.S. critical infrastructure entities. The campaign started months prior, leveraging advanced persistent threat (APT) tactics such as lateral movement, encrypted C2 channels, and sophisticated evasion techniques to bypass network defenses and persist undetected. This led to extensive exfiltration of sensitive data and raised major concerns about the resilience of core U.S. operational systems.
The BRICKSTORM attack signals a rising tide of highly targeted intrusions on virtualization platforms, as nation-state actors adopt increasingly stealthy and persistent approaches. Organizations must now contend with the growing complexity and scale of APT operations, which often elude legacy tools and monitoring strategies.
Why This Matters Now
This incident demonstrates that state actors are exploiting virtualization environments using custom malware to sustain covert access to critical infrastructure. The urgency lies in the potential for operational disruption and data loss at national scale, underscoring the need for advanced segmentation, encrypted traffic controls, and robust monitoring of both east-west and egress traffic to detect stealthy threats.
Attack Path Analysis
Adversaries from the PRC leveraged exposed management interfaces or stolen credentials to deploy the BRICKSTORM backdoor within VMware vSphere and Windows hybrid-cloud environments. Following initial access, they escalated privileges, possibly via local exploitation or credential abuse, to gain administrative control. Attackers then moved laterally through internal east-west traffic, pivoting across virtualized and multi-cloud assets. BRICKSTORM established persistent command and control connections for long-term remote management. Sensitive data was exfiltrated through covert or encrypted channels, bypassing standard outbound filters. Ultimately, the attackers maintained stealthy presence, potentially disrupting operations or facilitating further compromise.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited exposed management interfaces or weak credentials to infiltrate VMware vSphere or Windows hosts, deploying the BRICKSTORM backdoor for persistent access.
Related CVEs
CVE-2025-41244
CVSS 7.8A local privilege escalation vulnerability in VMware Aria Operations and VMware Tools allows a non-privileged user to gain root access on a virtual machine if certain VMware services are running.
Affected Products:
VMware Aria Operations – 8.x
VMware VMware Tools – 11.x, 12.x, 13.x
Exploit Status:
exploited in the wildCVE-2023-34048
CVSS 9.8An out-of-bounds write vulnerability in VMware vCenter Server allows remote code execution by attackers with network access.
Affected Products:
VMware vCenter Server – 7.0, 8.0
Exploit Status:
exploited in the wildCVE-2023-20867
CVSS 7An authentication bypass vulnerability in VMware Tools allows a compromised ESXi host to execute commands and transfer files to and from guest VMs without authentication.
Affected Products:
VMware VMware Tools – 11.x, 12.x
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Command and Scripting Interpreter
Boot or Logon Autostart Execution: Shortcut Modification
Ingress Tool Transfer
Obfuscated Files or Information
Process Injection
Server Software Component: Web Shell
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – MFA for All Access to the CDE
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Continuous Identity and Access Verification
Control ID: Identity – 1
NIS2 Directive – Implementation of Technical and Organizational Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Critical infrastructure targeting by PRC APT actors using BRICKSTORM backdoor threatens national security through VMware vSphere compromise and long-term persistence capabilities.
Information Technology/IT
VMware vSphere environments face sophisticated backdoor attacks requiring zero trust segmentation, east-west traffic monitoring, and enhanced Kubernetes security for client protection.
Financial Services
APT threats demand immediate encrypted traffic inspection, egress security enforcement, and anomaly detection to prevent data exfiltration and maintain regulatory compliance.
Health Care / Life Sciences
HIPAA-regulated environments need multicloud visibility, threat detection systems, and secure hybrid connectivity to protect against persistent backdoor access and lateral movement.
Sources
- CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systemshttps://thehackernews.com/2025/12/cisa-reports-prc-hackers-using.htmlVerified
- Broadcom finally patches dangerous VMware zero-day exploited by Chinese hackershttps://www.techradar.com/pro/security/broadcom-finally-patches-dangerous-vmware-zero-day-exploited-by-chinese-hackersVerified
- Chinese state hackers may be using VMware Tools flaw to hack US systems - so patch now, CISA warnshttps://www.techradar.com/pro/security/chinese-state-hackers-may-be-using-vmware-tools-flaw-to-hack-us-systems-so-patch-now-cisa-warnsVerified
- Chinese hackers used Brickworm malware to breach critical US infrastructurehttps://www.techradar.com/pro/security/chinese-hackers-used-brickworm-malware-to-breach-critical-us-infrastructureVerified
- Chinese hackers are using 'stealthy and resilient' Brickstorm malware to target VMware servers and hide in networks for months at a timehttps://www.itpro.com/security/malware/chinese-hackers-are-using-stealthy-and-resilient-brickstorm-malware-to-target-vmware-servers-and-hide-in-networks-for-months-at-a-timeVerified
- CISA and Partners Release Joint Advisory on Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage Systemshttps://www.cisa.gov/news-events/alerts/2025/08/27/cisa-and-partners-release-joint-advisory-countering-chinese-state-sponsored-actors-compromiseVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, centralized policy, robust egress filtering, and threat detection would have severely limited the attacker’s ability to move laterally, exfiltrate data, or maintain control. CNSF capabilities such as east-west security, inline IPS, and real-time observability could have detected or blocked key stages of the BRICKSTORM attack.
Control: Cloud Firewall (ACF)
Mitigation: Blocked or reduced attack surface exposure at cloud perimeters.
Control: Multicloud Visibility & Control
Mitigation: Alerted on abnormal privileged access and provided audit trails.
Control: Zero Trust Segmentation
Mitigation: Prevented unauthorized east-west movement by enforcing least privilege between workloads.
Control: Inline IPS (Suricata)
Mitigation: Detected and blocked known malicious C2 traffic patterns in real-time.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked unauthorized outbound transfers and alerted on high-risk exfiltration.
Early detection and automated incident response limited attacker dwell time and risk.
Impact at a Glance
Affected Business Functions
- IT Operations
- Data Management
- Network Security
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive internal communications, customer data, and intellectual property due to unauthorized access and data exfiltration by threat actors.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce least privilege policies and microsegmentation to prevent lateral movement across workloads.
- • Deploy centralized cloud firewalls and inline IPS to detect and stop unauthorized inbound and outbound traffic.
- • Implement comprehensive egress security to block unapproved data transfers and exfiltration attempts.
- • Continuously monitor East-West traffic with anomaly detection to detect covert remote access and privilege abuse.
- • Enhance cloud visibility and auditability to quickly investigate and respond to privileged access or infrastructure anomalies.



