Chinese APT deploys new malware to keep access to hacked networks
A Chinese Advanced Persistent Threat (APT) group, tracked as UNC5221 (VerdantBamboo), has been conducting a prolonged espionage campaign targeting organizations in the United States, primarily leveraging the Brickstorm backdoor and additional malware like Plenet and AgentPSD. The group gained initial access over 18 months prior and repeatedly compromised victim networks, including MSPs and various technology companies, utilizing sophisticated techniques to evade detection and blend in with legitimate network traffic. This ongoing activity highlights the persistent threat posed by state-sponsored actors and the importance of robust security measures, particularly against living-off-the-land techniques.
The UNC5221 group, also known as VerdantBamboo, has been systematically infiltrating networks since at least 2023, initially focusing on exploiting zero-day vulnerabilities in edge devices. Their tactics involved gaining access through MSPs and utilizing the Brickstorm backdoor, a sophisticated malware implant developed in both Golang and Rust, to maintain persistent access. The group’s ability to remain undetected for over a year, coupled with subsequent re-entries into compromised networks after remediation efforts, demonstrates a significant level of operational sophistication. Volexity researchers uncovered multiple instances of this activity, including targeting VMware vSphere servers and Dell RecoverPoint for Virtual Machines with Brickstorm, alongside the deployment of Plenet (Grimbolt) and AgentPSD.
The investigation revealed a complex, multi-stage attack chain. Initially, UNC5221 gained a foothold through compromised Egnyte Storage Sync systems and SSL VPNs, using Brickstorm to establish a covert presence. Subsequently, they leveraged this access to compromise Microsoft 365 environments and deployed Plenet to a Synology NAS device. A second intrusion involved the attackers gaining access to a firewall and deploying AgentPSD as a fallback persistence mechanism. The group’s deliberate shutdown of C2 infrastructure before detection further underscores their proactive approach to mitigating investigation efforts.
This incident highlights the risks associated with prolonged access to networks and the potential for attackers to exploit vulnerabilities across multiple layers of an organization’s infrastructure. The use of living-off-the-land techniques, combined with the deployment of diverse malware families, makes attribution and remediation particularly challenging.