VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
A China-based cyber espionage group, VerdantBamboo, deployed a BSD variant of the BRICKSTORM backdoor and the PLENET malware family on Linux appliances to target a victim organization. The attack involved exploiting vulnerabilities, stealing credentials, and leveraging a Managed Services Provider (MSP) to expand its reach and compromise additional systems.
VerdantBamboo, linked to groups like Clay Typhoon, UNC5221, and Warp Panda, targeted a victim organization through a series of actions beginning at least 18 months prior. The initial compromise occurred via a local privilege escalation flaw in an Egnyte Storage Sync system, leading to the deployment of BRICKSTORM and subsequent access to the victim's Microsoft 365 (M365) environment. The group utilized proxying capabilities and stolen credentials to blend in with network traffic and evade security controls. Following remediation, VerdantBamboo staged a return, gaining access to the victim's firewall and subsequently deploying malware to a Synology NAS appliance, further expanding its presence within the organization’s network. The MSP’s pfSense firewall was also infected with a BRICKSTORM variant, highlighting the group’s ability to leverage third-party infrastructure for malicious activity.
