BRICKSTORM — Malware Profile
BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of other malware, and the exfiltration of data. BRICKSTORM has also been created from a .NET application using ahead-of-time (AOT) compilation to blend in within victim environments. BRICKSTORM was first observed in April 2024. BRICKSTORM has previously been leveraged by People's Republic of China (PRC) state-nexus actors identified as UNC6201, UNC5221, WARP PANDA, PunyToad, and SYLVANITE.
MITRE ATT&CK techniques (25)
- T1005 Data from Local System
- T1027 Obfuscated Files or Information
- T1027.013 Encrypted/Encoded File
- T1036.005 Match Legitimate Resource Name or Location
- T1041 Exfiltration Over C2 Channel
- T1057 Process Discovery
- T1059.004 Unix Shell
- T1070.004 File Deletion
- T1070.010 Relocate Malware
- T1071.001 Web Protocols
- T1071.004 DNS
- T1083 File and Directory Discovery
- T1090.001 Internal Proxy
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1132.001 Standard Encoding
- T1140 Deobfuscate/Decode Files or Information
- T1489 Service Stop
- T1543 Create or Modify System Process
- T1568 Dynamic Resolution
- T1572 Protocol Tunneling
- T1573.002 Asymmetric Cryptography
- T1574.007 Path Interception by PATH Environment Variable
- T1678 Delay Execution
- T1690 Prevent Command History Logging