PULSE NAME
BRICKSTORM Backdoor
WHITE PetrP.73 2025-12-29 Modified: 2026-01-28
49
IOCs
MEDIUM VOLUME
BRICKSTORM is a backdoor malware identified as being utilized by state-sponsored cyber actors from the People's Republic of China (PRC) to gain long-term access to victim systems. Both the Cybersecurity and Infrastructure Security Agency (CISA) and its partner organizations have provided detailed insights into this malware, based on analyses of multiple samples. The malware is categorized as a custom Executable and Linkable Format (ELF) backdoor, built predominantly with Go, with updates included for additional samples by late December 2025. The initial access vector for BRICKSTORM involved exploiting a web server within a victim's demilitarized zone (DMZ), where attackers used a web shell-indicative of the technique T1505.003-to infiltrate the organization. Following this, they elevated their privileges with the sudo command (T1548.003) and established persistence by placing the malware in the system's /etc/sysconfig/ directory, configuring the init file to ensure the malware executes upon system boot.
Indicators of Compromise (12 / 49 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 10d811029f6e5f58cd06143d6353d3b05bc06d0f 2025-12-29
FileHash-SHA1 38f6baad1dff7466a07eb456808cc8aa46a3e50c 2025-12-29
FileHash-SHA1 44a3d3f15ef75d9294345462e1b82272b0d11985 2025-12-29
FileHash-SHA1 7cec4d74931d925996b03a75da0d79e95f47ed86 2025-12-29
FileHash-SHA1 97001baaa379bcd83677dca7bc5b8048fdfaaddc 2025-12-29
FileHash-SHA1 9bf4c786ebd68c0181cfe3eb85d2fd202ed12c54 2025-12-29
FileHash-SHA1 b439749a581ac5a29b5c9d91fc092bf4ceaa76a4 SHA1 of 320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759 2025-12-29
FileHash-SHA1 c3549d4e5e39a11f609fc6fbf5cc1f2c0ec272b4 2025-12-29
FileHash-SHA1 de28546ec356c566cd8bca205101a733e9a4a22d 2025-12-29
FileHash-SHA1 f639d9404c03af86ce452db5c5e0c528b81dc0d7 2025-12-29
FileHash-SHA1 fa664bb3369d4a48db88f4e8d7364f7582f64313 2025-12-29
FileHash-SHA1 fb11c6caa4ea844942fe97f46d7eb42bc76911ab 2025-12-29