PULSE NAME
BRICKSTORM Backdoor
WHITE PetrP.73 2025-12-29 Modified: 2026-01-28
49
IOCs
MEDIUM VOLUME
BRICKSTORM is a backdoor malware identified as being utilized by state-sponsored cyber actors from the People's Republic of China (PRC) to gain long-term access to victim systems. Both the Cybersecurity and Infrastructure Security Agency (CISA) and its partner organizations have provided detailed insights into this malware, based on analyses of multiple samples. The malware is categorized as a custom Executable and Linkable Format (ELF) backdoor, built predominantly with Go, with updates included for additional samples by late December 2025. The initial access vector for BRICKSTORM involved exploiting a web server within a victim's demilitarized zone (DMZ), where attackers used a web shell-indicative of the technique T1505.003-to infiltrate the organization. Following this, they elevated their privileges with the sudo command (T1548.003) and established persistence by placing the malware in the system's /etc/sysconfig/ directory, configuring the init file to ensure the malware executes upon system boot.
Indicators of Compromise (4 / 49 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
URL https://149.112.112.112/dns-query' 2025-12-29
URL https://45.90.28.160/dns-query' 2025-12-29
URL https://45.90.30.160/dns-query' 01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b 2025-12-29
URL https://9.9.9.11/dns-query' 2025-12-29