The Containment Era is here. →Explore

Executive Summary

In late 2025, PRC state-sponsored cyber actors launched a sophisticated espionage campaign using the BRICKSTORM malware, targeting government and information technology sectors. The threat actors gained initial access via a compromised web server in victim DMZs, progressed laterally to internal VMware vCenter servers, and deployed BRICKSTORM to maintain deep persistence in both VMware vSphere and Windows environments. Leveraging advanced encrypted communication channels, stolen credentials, and techniques such as DNS-over-HTTPS and rogue virtual machines, the actors exfiltrated sensitive data while evading detection for extended periods.

This incident underscores the evolving tactics of nation-state adversaries, who now frequently employ modular, stealthy malware to attack critical infrastructure. The widespread use of cloud and virtualization platforms in public sector IT environments makes these organizations particularly vulnerable to such persistent threats.

Why This Matters Now

The BRICKSTORM campaign highlights the urgent need for organizations to secure hybrid cloud and virtualization environments, as attackers increasingly exploit internal infrastructure. The incident emphasizes the importance of network segmentation, identity protection, and monitoring east-west traffic to mitigate stealthy, long-term compromises by state-sponsored actors.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident exposed gaps in east-west traffic visibility, weak lateral movement controls, insufficient network segmentation, and a lack of encrypted traffic monitoring within hybrid IT environments.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust controls—such as network segmentation, east-west traffic monitoring, strong egress policy, advanced threat detection, and encrypted transport—would have raised barriers at every phase of the BRICKSTORM intrusion, from initial access to lateral movement and exfiltration. CNSF capabilities directly align to detecting, containing, or preventing credential abuse, stealthy lateral movement, encrypted C2, and data theft in cloud and hybrid environments.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Unauthorized access to DMZ-facing workloads would be blocked or limited.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Abnormal credential access and privilege abuse attempts would be detected rapidly.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Unapproved internal traffic between segments would be blocked or flagged.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Suspicious encrypted traffic patterns and known C2 signatures would trigger alerts or be blocked.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unauthorized data exfiltration via unsanctioned protocols is blocked or alerted.

Impact (Mitigations)

Anomalous host and network behavior indicates persistence and unauthorized workload creation.

Impact at a Glance

Affected Business Functions

  • Government Services
  • Information Technology
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive government and corporate data, including credentials and proprietary information.

Recommended Actions

  • Implement Zero Trust Segmentation and microsegmentation to restrict access between DMZ, workloads, and management resources.
  • Enforce comprehensive east-west and egress traffic controls to prevent lateral movement and data exfiltration using policy-driven filtering.
  • Deploy inline IPS/IDS for detection of C2 activity, DNS-over-HTTPS abuse, and protocol anomalies within cloud and hybrid networks.
  • Maintain centralized multicloud visibility for real-time monitoring, anomaly baselining, and rapid detection of credential or privilege misuse.
  • Continuously update and validate network inventories, hunt for persistent malware, and automate incident response leveraging CNSF capabilities.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image