Chinese hackers reportedly targeting government entities using ‘Brickstorm’ malware


Hackers with links to China reportedly successfully infiltrated a number of unnamed government and tech entities using advanced malware. As reported by , cybersecurity agencies from the US and Canada confirmed the attack, which used a backdoor known as “Brickstorm” to target organizations using the VMware vSphere cloud computing platform.

As detailed in a published by the Canadian Centre for Cyber Security on December 4, PRC state-sponsored hackers maintained “long-term persistent access” to an unnamed victim’s internal network. After compromising the affected platform, the cybercriminals were able to steal credentials, manipulate sensitive files and create “rogue, hidden VMs” (virtual machines), effectively seizing control unnoticed. The attack could have begun as far back as April 2024 and lasted until at least September of this year.

The malware analysis report published by the Canadian Cyber Centre, with assistance from The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), cites eight different Brickstorm malware samples. It is not clear exactly how many organizations in total were either targeted or successfully penetrated.

In an email to Reuters, a spokesperson for VMware vSphere owner Broadcom said it was aware of the alleged hack, and encouraged its customers to download up-to-date security patches whenever possible. In September, the Google Threat Intelligence Group its own report on Brickstorm, in which it urged organizations to “reevaluate their threat model for appliances and conduct hunt exercises” against specified threat actors.



Source link

  • Related Posts

    Jon M. Chu Says AI Couldn’t Have Made One of the Best Moments in ‘Wicked’

    If there’s anyone who understands the importance of viral marketing, it’s Wicked: For Good director Jon M. Chu. At WIRED’s Big Interview event in San Francisco, the onetime YouTuber and…

    Don’t use ‘admin’: UK’s top 20 most-used passwords revealed as scams soar | Scams

    It is a hacker’s dream. Even in the face of repeated warnings to protect online accounts, a new study reveals that “admin” is the most commonly used password in the…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    UFC 323 results: Payton Talbott earns win over retiring Henry Cejudo in thriller

    UFC 323 results: Payton Talbott earns win over retiring Henry Cejudo in thriller

    WATCH: The real cost of Christmas

    WATCH:  The real cost of Christmas

    Jon M. Chu Says AI Couldn’t Have Made One of the Best Moments in ‘Wicked’

    Jon M. Chu Says AI Couldn’t Have Made One of the Best Moments in ‘Wicked’

    Economists Judge Brexit Bill to Be Worse Than Ever Just as Politics Is Shifting

    US tariffs prompt surge in Chinese exports to south-east Asia

    US tariffs prompt surge in Chinese exports to south-east Asia

    In true roguelike fashion, Slay the Spire 2 is only being made because of a 50/50 coin flip

    In true roguelike fashion, Slay the Spire 2 is only being made because of a 50/50 coin flip