TF-MAL-elf.brickstorm
📛 Threat Title
Malware family: BRICKSTORM
Description
ThreatFox malware family `elf.brickstorm`. Printable name: BRICKSTORM.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.brickstorm
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.brickstorm
IOC database
- Type
- domain
- Value
elf.brickstorm- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.brickstorm
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.brickstorm
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.nviso.eu
NVISO has recently identified new information related to BRICKSTORM , a previously identified1 backdoor linked to the China-nexus cluster UNC5221. This report provides a technical analysis of two newly identified BRICKSTORM samples which were affecting Windows environments. These samples are part of the BRICKSTORM backdoor family , previously only sighted on a Linux vCenter server. The newly ...
-
web:cloud.google.com
BRICKSTORM is a stealthy backdoor used by suspected China-nexus actors for long-term espionage.
-
web:media.defense.gov
Introduction Note: This Malware Analysis Report was originally published Dec. 4, 2025, to share indicators of compromise (IOCs) and detection signatures for BRICKSTORM malware . The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Canadian Centre for Cyber Security (Cyber Centre) have updated this Malware Analysis Report three times.
-
web:thehackernews.com
UNC5221 uses BRICKSTORM malware to maintain 393-day stealthy access to U.S. SaaS, legal, and tech sectors.
-
web:www.cisa.gov
The cyber actors used BRICKSTORM for persistent access from at least April 2024 through at least Sep. 3, 2025. CISA, NSA, and Cyber Centre urge organizations to use the IOCs and detection signatures in this Malware Analysis Report to identify BRICKSTORM malware samples. If identified, follow the guidance in the Incident Response section.
-
web:www.cyber.gc.ca
Common forms of malware include computer viruses, worms, Trojans, spyware, and adware. analysis report. This joint report warns that People's Republic of China (PRC) state-sponsored threat actors are using Brickstorm malware for long-term persistence on victims' systems.
-
web:www.hstoday.us
The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency, and Canadian Centre for Cyber Security have released an update to the Malware Analysis Report BRICKSTORM Backdoor with indicators of compromise (IOCs) and detection signatures for additional BRICKSTORM samples.
-
web:www.lowenstein.com
On Dec. 4, 2025, the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency, and Canadian Centre for Cyber Security released a report, Malware Analysis Report AR25‑338A ( BRICKSTORM Backdoor), which confirms our initial assessment and provides expanded technical details, detection signatures, and mitigation guidance.
-
web:www.netsecurity.com
On December 4, 2025, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA) and the Canadian Centre for Cyber Security (Cyber Centre), released Malware Analysis Report AR25-338A detailing a significant cyber threat: BRICKSTORM , a highly advanced backdoor attributed to state-sponsored actors from the People's Republic of China ...
-
web:www.nsa.gov
FORT MEADE, Md. - The National Security Agency (NSA) is joining the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre for Cyber Security to detail the broad campaign of China state-sponsored cyber actors using the BRICKSTORM malware for long-term persistence on victim systems. BRICKSTORM malware is a sophisticated backdoor that provides capabilities for secure ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.