The Containment Era is here. →Explore

Executive Summary

In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported that state-sponsored hackers affiliated with the People's Republic of China (PRC) utilized a newly identified backdoor dubbed BRICKSTORM to infiltrate and maintain long-term access within VMware vSphere and Windows environments of U.S. critical infrastructure entities. The campaign started months prior, leveraging advanced persistent threat (APT) tactics such as lateral movement, encrypted C2 channels, and sophisticated evasion techniques to bypass network defenses and persist undetected. This led to extensive exfiltration of sensitive data and raised major concerns about the resilience of core U.S. operational systems.

The BRICKSTORM attack signals a rising tide of highly targeted intrusions on virtualization platforms, as nation-state actors adopt increasingly stealthy and persistent approaches. Organizations must now contend with the growing complexity and scale of APT operations, which often elude legacy tools and monitoring strategies.

Why This Matters Now

This incident demonstrates that state actors are exploiting virtualization environments using custom malware to sustain covert access to critical infrastructure. The urgency lies in the potential for operational disruption and data loss at national scale, underscoring the need for advanced segmentation, encrypted traffic controls, and robust monitoring of both east-west and egress traffic to detect stealthy threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach highlighted insufficient segmentation, inadequate east-west traffic monitoring, and gaps in encrypted traffic analysis that allowed persistent undetected access, impacting compliance with HIPAA, PCI DSS, NIST 800-53, and Zero Trust mandates.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, centralized policy, robust egress filtering, and threat detection would have severely limited the attacker’s ability to move laterally, exfiltrate data, or maintain control. CNSF capabilities such as east-west security, inline IPS, and real-time observability could have detected or blocked key stages of the BRICKSTORM attack.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked or reduced attack surface exposure at cloud perimeters.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Alerted on abnormal privileged access and provided audit trails.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Prevented unauthorized east-west movement by enforcing least privilege between workloads.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detected and blocked known malicious C2 traffic patterns in real-time.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Blocked unauthorized outbound transfers and alerted on high-risk exfiltration.

Impact (Mitigations)

Early detection and automated incident response limited attacker dwell time and risk.

Impact at a Glance

Affected Business Functions

  • IT Operations
  • Data Management
  • Network Security
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive internal communications, customer data, and intellectual property due to unauthorized access and data exfiltration by threat actors.

Recommended Actions

  • Enforce least privilege policies and microsegmentation to prevent lateral movement across workloads.
  • Deploy centralized cloud firewalls and inline IPS to detect and stop unauthorized inbound and outbound traffic.
  • Implement comprehensive egress security to block unapproved data transfers and exfiltration attempts.
  • Continuously monitor East-West traffic with anomaly detection to detect covert remote access and privilege abuse.
  • Enhance cloud visibility and auditability to quickly investigate and respond to privileged access or infrastructure anomalies.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image