Executive Summary
In September 2025, cybersecurity firm Volexity identified a prolonged cyber espionage campaign by the Chinese state-sponsored group VerdantBamboo, also known as UNC5221. The attackers exploited a local privilege escalation vulnerability in an Egnyte Storage Sync appliance to deploy a BSD variant of the BRICKSTORM backdoor, maintaining undetected access for at least 18 months. This access facilitated further infiltration into the victim's Microsoft 365 environment and the deployment of additional malware, including PLENET and AGENTPSD, on various network appliances. The campaign underscores the increasing targeting of network appliances and storage systems by sophisticated threat actors, exploiting their lack of endpoint detection capabilities to establish long-term persistence. Organizations are urged to enhance monitoring and security measures for such devices to mitigate similar threats.
Why This Matters Now
The VerdantBamboo incident highlights the critical need for organizations to secure network appliances and storage systems, which are increasingly targeted by sophisticated threat actors exploiting their lack of endpoint detection capabilities to establish long-term persistence.
Attack Path Analysis
VerdantBamboo initially compromised the victim's Egnyte Storage Sync system by exploiting a local privilege escalation vulnerability, deploying the BRICKSTORM backdoor. They escalated privileges by exploiting misconfigured sudo rules, gaining elevated access. Using BRICKSTORM's proxying capabilities, they moved laterally to access the victim's Microsoft 365 environment. The attackers established command and control by deploying additional malware, including PLENET and AGENTPSD, on various appliances. They exfiltrated data by leveraging compromised credentials and malware to access and extract sensitive information. The impact included prolonged unauthorized access, data exfiltration, and potential disruption of services.
Kill Chain Progression
Initial Compromise
Description
VerdantBamboo exploited a local privilege escalation vulnerability in the Egnyte Storage Sync system to deploy the BRICKSTORM backdoor.
Related CVEs
CVE-2026-22769
CVSS 10A critical vulnerability in Dell RecoverPoint for Virtual Machines allows remote attackers to execute arbitrary code.
Affected Products:
Dell RecoverPoint for Virtual Machines – All versions prior to the patch
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Create or Modify System Process: Windows Service
Application Layer Protocol: Web Protocols
Command and Scripting Interpreter: PowerShell
Hijack Execution Flow: DLL Side-Loading
Remote Services: Remote Desktop Protocol
OS Credential Dumping: LSASS Memory
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical infrastructure targeted by VerdantBamboo APT using BRICKSTORM backdoor on Linux appliances, threatening network equipment and encrypted communications similar to Salt Typhoon attacks.
Government Administration
High-value espionage target for China-nexus Clay Typhoon group deploying multiple malware families on Linux systems, compromising sensitive government data and communications infrastructure.
Utilities
Linux-based industrial control systems vulnerable to PLENET and AGENTPSD malware deployment, enabling lateral movement and potential disruption of critical utility operations and services.
Defense/Space
Strategic APT espionage operations targeting defense contractors through BSD BRICKSTORM variants, threatening classified information and mission-critical Linux-based defense systems and communications.
Sources
- VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Applianceshttps://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.htmlVerified
- VerdantBamboo: Just Another BRICKSTORM in the Firewallhttps://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/Verified
- Chinese APT deploys new malware to keep access to hacked networkshttps://www.bleepingcomputer.com/news/security/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the vulnerability may have been constrained, reducing the likelihood of successful backdoor deployment.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited, reducing the scope of their elevated access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may have been restricted, reducing their ability to access additional systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels could have been constrained, reducing their control over compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been limited, reducing the volume of data they could extract.
The overall impact of the attack could have been reduced, limiting unauthorized access duration and data loss.
Impact at a Glance
Affected Business Functions
- Data Storage and Management
- Network Security
- Cloud Services
Estimated downtime: 14 days
Estimated loss: $500,000
Potential exposure of sensitive corporate data and client information due to compromised storage and network systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit access to critical systems.
- • Enforce East-West Traffic Security to monitor and control internal communications, detecting unauthorized access attempts.
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and control outbound traffic.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network activities across all environments.
- • Apply Inline IPS (Suricata) to detect and prevent exploitation attempts by identifying known malicious patterns.



