The Containment Era is here. →Explore

Executive Summary

In September 2025, cybersecurity firm Volexity identified a prolonged cyber espionage campaign by the Chinese state-sponsored group VerdantBamboo, also known as UNC5221. The attackers exploited a local privilege escalation vulnerability in an Egnyte Storage Sync appliance to deploy a BSD variant of the BRICKSTORM backdoor, maintaining undetected access for at least 18 months. This access facilitated further infiltration into the victim's Microsoft 365 environment and the deployment of additional malware, including PLENET and AGENTPSD, on various network appliances. The campaign underscores the increasing targeting of network appliances and storage systems by sophisticated threat actors, exploiting their lack of endpoint detection capabilities to establish long-term persistence. Organizations are urged to enhance monitoring and security measures for such devices to mitigate similar threats.

Why This Matters Now

The VerdantBamboo incident highlights the critical need for organizations to secure network appliances and storage systems, which are increasingly targeted by sophisticated threat actors exploiting their lack of endpoint detection capabilities to establish long-term persistence.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed vulnerabilities in network appliances and storage systems lacking endpoint detection capabilities, highlighting the need for enhanced security measures and compliance protocols for such devices.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit the vulnerability may have been constrained, reducing the likelihood of successful backdoor deployment.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been limited, reducing the scope of their elevated access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement may have been restricted, reducing their ability to access additional systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control channels could have been constrained, reducing their control over compromised systems.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts may have been limited, reducing the volume of data they could extract.

Impact (Mitigations)

The overall impact of the attack could have been reduced, limiting unauthorized access duration and data loss.

Impact at a Glance

Affected Business Functions

  • Data Storage and Management
  • Network Security
  • Cloud Services
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive corporate data and client information due to compromised storage and network systems.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement and limit access to critical systems.
  • Enforce East-West Traffic Security to monitor and control internal communications, detecting unauthorized access attempts.
  • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and control outbound traffic.
  • Utilize Multicloud Visibility & Control to gain comprehensive insights into network activities across all environments.
  • Apply Inline IPS (Suricata) to detect and prevent exploitation attempts by identifying known malicious patterns.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image