PULSE NAME
BRICKSTORM Backdoor
WHITE PetrP.73 2025-12-29 Modified: 2026-01-28
49
IOCs
MEDIUM VOLUME
BRICKSTORM is a backdoor malware identified as being utilized by state-sponsored cyber actors from the People's Republic of China (PRC) to gain long-term access to victim systems. Both the Cybersecurity and Infrastructure Security Agency (CISA) and its partner organizations have provided detailed insights into this malware, based on analyses of multiple samples. The malware is categorized as a custom Executable and Linkable Format (ELF) backdoor, built predominantly with Go, with updates included for additional samples by late December 2025. The initial access vector for BRICKSTORM involved exploiting a web server within a victim's demilitarized zone (DMZ), where attackers used a web shell-indicative of the technique T1505.003-to infiltrate the organization. Following this, they elevated their privileges with the sudo command (T1548.003) and established persistence by placing the malware in the system's /etc/sysconfig/ directory, configuring the init file to ensure the malware executes upon system boot.
Indicators of Compromise (12 / 49 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0a4fa52803a389311a9ddc49b7b19138 2025-12-29
FileHash-MD5 18f895e24fe1181bb559215ff9cf6ce3 2025-12-29
FileHash-MD5 34d6af5ae2ab7a08fa474358a0b95539 2025-12-29
FileHash-MD5 39111508bfde89ce6e0fe6abe0365552 2025-12-29
FileHash-MD5 6c20a810134025a9f05cf312d4b34967 2025-12-29
FileHash-MD5 82bf31e7d768e6d4d3bc7c8c8ef2b358 2025-12-29
FileHash-MD5 8e4c88d00b6eb46229a1ed7001451320 2025-12-29
FileHash-MD5 9c44bc9373377831c45dd0ac2661a28e MD5 of 320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759 2025-12-29
FileHash-MD5 a02469742f7b0bc9a8ab5e26822b3fa8 2025-12-29
FileHash-MD5 a52e36a70b5e0307cbcaa5fd7c97882c 2025-12-29
FileHash-MD5 d1f608cfb395d9274aa52b6a524d9fb5 2025-12-29
FileHash-MD5 dbca28ad420408850a94d5c325183b28 2025-12-29