The Containment Era is here. →Explore

Executive Summary

In 2025, Google’s Threat Intelligence Group uncovered that the UNC5221 threat actor, suspected to have ties to China, used the Brickstorm malware to conduct stealthy, long-term espionage campaigns against U.S. legal and technology organizations, SaaS providers, and BPOs. The attackers exploited zero-day vulnerabilities in enterprise edge devices lacking EDR protection, establishing persistent access for an average dwell time of over a year. Brickstorm enabled credential theft, lateral movement, and data exfiltration, often targeting email and sensitive code repositories, all while obfuscating forensic traces and regularly changing infrastructure.

This incident highlights a growing trend of persistent, supply-chain-oriented APT attacks targeting critical sectors via unmonitored infrastructure. It underscores the importance of timely patching, segmentation, and improved visibility for hybrid and edge environments facing increasing risks from nation-state adversaries.

Why This Matters Now

Nation-state APTs are increasingly exploiting unmanaged or edge devices with sophisticated malware and anti-forensic methods, bypassing traditional detection. With many organizations migrating to hybrid architectures, this exposes critical gaps and accelerates the need for robust zero trust, segmentation, and threat detection strategies to prevent long-term data theft.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The campaign exploited poor segmentation, lack of encrypted east-west traffic, and limited visibility/control over unmanaged edge devices, revealing deficiencies across NIST, PCI, and HIPAA security domains.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Robust microsegmentation, east-west traffic controls, credential-aware egress enforcement, threat detection, and encrypted workload flows could have sharply limited attacker movement and exfiltration. CNSF controls provide visibility and granular policy enforcement at each phase to detect, block, or constrain sophisticated, multi-cloud espionage operations like Brickstorm.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked unauthorized inbound connections to vulnerable management interfaces.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Prevented excessive privilege elevation and credential sprawl across tiers.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detected and blocked anomalous internal movement and unauthorized SSH sessions.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Flagged and prevented known C2 patterns and protocol abuse, even over encrypted flows.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Blocked unauthorized data flows and exfiltration channels to external destinations.

Impact (Mitigations)

Generated alerts on suspicious cleanup, persistence abuses, and trace deletion patterns.

Impact at a Glance

Affected Business Functions

  • Legal Services
  • Technology Development
  • Software-as-a-Service Operations
  • Business Process Outsourcing
Operational Disruption

Estimated downtime: 30 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Sensitive client data, proprietary software code, and confidential legal documents were exfiltrated, leading to potential legal liabilities and loss of competitive advantage.

Recommended Actions

  • Deploy Zero Trust Segmentation across all hybrid/cloud workloads to restrict movement from compromised entry points.
  • Enforce rigorous egress filtering and application-layer controls to block unsanctioned outbound data flows.
  • Implement granular east-west traffic inspection to detect and stop lateral movement, credential abuse, and privilege escalation.
  • Leverage real-time threat detection and baselining tools to identify and respond rapidly to anomalous behaviors and stealthy persistence.
  • Ensure all sensitive management interfaces and APIs are protected by workload identity, microsegmentation, and least-privilege policy.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image