s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.brickstorm

📛 Threat Title

Malware family: BRICKSTORM

Category: BRICKSTORM First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.brickstorm`. Printable name: BRICKSTORM.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.brickstorm VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.brickstorm

IOC database

Type
domain
Value
elf.brickstorm
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.brickstorm

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.brickstorm

References (1)

Remediations (10)

  • web:blog.nviso.eu

    NVISO has recently identified new information related to BRICKSTORM , a previously identified1 backdoor linked to the China-nexus cluster UNC5221. This report provides a technical analysis of two newly identified BRICKSTORM samples which were affecting Windows environments. These samples are part of the BRICKSTORM backdoor family , previously only sighted on a Linux vCenter server. The newly ...

  • web:cloud.google.com

    BRICKSTORM is a stealthy backdoor used by suspected China-nexus actors for long-term espionage.

  • web:media.defense.gov

    Introduction Note: This Malware Analysis Report was originally published Dec. 4, 2025, to share indicators of compromise (IOCs) and detection signatures for BRICKSTORM malware . The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Canadian Centre for Cyber Security (Cyber Centre) have updated this Malware Analysis Report three times.

  • web:thehackernews.com

    UNC5221 uses BRICKSTORM malware to maintain 393-day stealthy access to U.S. SaaS, legal, and tech sectors.

  • web:www.cisa.gov

    The cyber actors used BRICKSTORM for persistent access from at least April 2024 through at least Sep. 3, 2025. CISA, NSA, and Cyber Centre urge organizations to use the IOCs and detection signatures in this Malware Analysis Report to identify BRICKSTORM malware samples. If identified, follow the guidance in the Incident Response section.

  • web:www.cyber.gc.ca

    Common forms of malware include computer viruses, worms, Trojans, spyware, and adware. analysis report. This joint report warns that People's Republic of China (PRC) state-sponsored threat actors are using Brickstorm malware for long-term persistence on victims' systems.

  • web:www.hstoday.us

    The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency, and Canadian Centre for Cyber Security have released an update to the Malware Analysis Report BRICKSTORM Backdoor with indicators of compromise (IOCs) and detection signatures for additional BRICKSTORM samples.

  • web:www.lowenstein.com

    On Dec. 4, 2025, the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency, and Canadian Centre for Cyber Security released a report, Malware Analysis Report AR25‑338A ( BRICKSTORM Backdoor), which confirms our initial assessment and provides expanded technical details, detection signatures, and mitigation guidance.

  • web:www.netsecurity.com

    On December 4, 2025, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA) and the Canadian Centre for Cyber Security (Cyber Centre), released Malware Analysis Report AR25-338A detailing a significant cyber threat: BRICKSTORM , a highly advanced backdoor attributed to state-sponsored actors from the People's Republic of China ...

  • web:www.nsa.gov

    FORT MEADE, Md. - The National Security Agency (NSA) is joining the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre for Cyber Security to detail the broad campaign of China state-sponsored cyber actors using the BRICKSTORM malware for long-term persistence on victim systems. BRICKSTORM malware is a sophisticated backdoor that provides capabilities for secure ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.