PULSE NAME
BRICKSTORM Backdoor
WHITE PetrP.73 2025-12-29 Modified: 2026-01-28
49
IOCs
MEDIUM VOLUME
BRICKSTORM is a backdoor malware identified as being utilized by state-sponsored cyber actors from the People's Republic of China (PRC) to gain long-term access to victim systems. Both the Cybersecurity and Infrastructure Security Agency (CISA) and its partner organizations have provided detailed insights into this malware, based on analyses of multiple samples. The malware is categorized as a custom Executable and Linkable Format (ELF) backdoor, built predominantly with Go, with updates included for additional samples by late December 2025. The initial access vector for BRICKSTORM involved exploiting a web server within a victim's demilitarized zone (DMZ), where attackers used a web shell-indicative of the technique T1505.003-to infiltrate the organization. Following this, they elevated their privileges with the sudo command (T1548.003) and established persistence by placing the malware in the system's /etc/sysconfig/ directory, configuring the init file to ensure the malware executes upon system boot.
Indicators of Compromise (21 / 49 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 013211c56caaa697914b5b5871e4998d0298902e336e373ebb27b7db30917eaf 2025-12-29
FileHash-SHA256 0e92009fc6519c837982b3fbfd42946e827de47b73a264d693739168533d07f4 2025-12-29
FileHash-SHA256 22c15a32b69116a46eb5d0f2b228cc37cd1b5915a91ec8f38df79d3eed1da26b 2025-12-29
FileHash-SHA256 28a16e782f04d9394b5dfa3363d41d9f5eecc206166aeffd73363d83734a026d 2025-12-29
FileHash-SHA256 2bf9bfa1f9bcbcad0eada7e3be8d380d809248f08609f6e9d971b37ce09f7e93 2025-12-29
FileHash-SHA256 320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759 2025-12-29
FileHash-SHA256 39b3d8a8aedffc1b40820f205f6a4dc041cd37262880e5030b008175c45b0c46 2025-12-29
FileHash-SHA256 57bd98dbb5a00e54f07ffacda1fea91451a0c0b532cd7d570e98ce2ff741c21d 2025-12-29
FileHash-SHA256 6a67a9769a55ec889a5dd4199b2fc08965d39d737838836853bc13c81c56a800 2025-12-29
FileHash-SHA256 6d42e9a0757670b9837034b5202d1673093577757b44bb0f0253f366413393e9 2025-12-29
FileHash-SHA256 73fe8b8fb4bd7776362fd356fdc189c93cf5d9f6724f6237d829024c10263fe5 2025-12-29
FileHash-SHA256 77b49c854afd6746fee393711b48979376fb910b34105c0e18a3fdc24ea31d5c 2025-12-29
FileHash-SHA256 aaf5569c8e349c15028bc3fac09eb982efb06eabac955b705a6d447263658e38 2025-12-29
FileHash-SHA256 b30041b986ee3231fd53522c9d0c57e4567d6c60959fa06c125dde2af558fc9f 2025-12-29
FileHash-SHA256 b3b6a992540da96375e4781afd3052118ad97cfe60ccf004d732f76678f6820a 2025-12-29
FileHash-SHA256 b91881cb1aa861138f2063ec130b2b01a8aaf0e3f04921e5cbfc61b09024bf12 2025-12-29
FileHash-SHA256 bfb3ffd46b21b2281374cd60bc756fe2dcc32486dcc156c9bd98f24101145454 2025-12-29
FileHash-SHA256 dfac2542a0ee65c474b91d3b352540a24f4e223f1b808b741cfe680263f0ee44 2025-12-29
FileHash-SHA256 ed907d39efd5750236b075ca9fbb1f090d7bf578578c38faab24210d298a60ae 2025-12-29
FileHash-SHA256 f7cda90174b806a34381d5043e89b23ba826abcc89f7abd520060a64475ed506 2025-12-29
FileHash-SHA256 fb22eea57e00b83edad50ee6e02320377efc10586584c476d5018dbba3643c32 2025-12-29