ATT&CKReferencesGoogle UNC5221 BRICKSTORM SPAWNCHIMERA April 2024

Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024

Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareBRICKSTORM

BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`.

T1040
Network Sniffing
MalwareSPAWNCHIMERA

SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control.

T1041
Exfiltration Over C2 Channel
MalwareBRICKSTORM

BRICKSTORM has uploaded files from the victim system to C2 servers.

T1055.002
Portable Executable Injection
MalwareSPAWNCHIMERA

SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process.

T1057
Process Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched for running processes to include web or dsmdm.

T1059.004
Unix Shell
MalwareBRICKSTORM

BRICKSTORM has executed shell commands using `/bin/sh`.

T1070.004
File Deletion
MalwareBRICKSTORM

BRICKSTORM has the ability to delete files and directories. BRICKSTORM also has deleted installer files after execution to reduce detection.

T1071.001
Web Protocols
MalwareBRICKSTORM

BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers. BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls.

T1071.004
DNS
MalwareBRICKSTORM

BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection.

T1082
System Information Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has obtained system information such as release, uptime, and current time.

T1083
File and Directory Discovery
MalwareBRICKSTORM

BRICKSTORM has identified specific files and directories within targeted hosts and systems for modification, execution, collection and exfiltration.

T1090.001
Internal Proxy
MalwareBRICKSTORM

BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic.

T1105
Ingress Tool Transfer
MalwareBRICKSTORM

BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.

T1518.001
Security Software Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has checked where SELinux is enabled on the targeted host.

T1559
Inter-Process Communication
MalwareSPAWNCHIMERA

SPAWNCHIMERA has leveraged IPC using a UNIX domain socket between the dsmdm process and the web process.

T1571
Non-Standard Port
MalwareSPAWNCHIMERA

SPAWNCHIMERA has the ability to bind on a localhost and listen on port 8300.

T1572
Protocol Tunneling
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications.

T1572
Protocol Tunneling
MalwareBRICKSTORM

BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket.

T1574
Hijack Execution Flow
MalwareSPAWNCHIMERA

SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process.

T1574.006
Dynamic Linker Hijacking
MalwareSPAWNCHIMERA

SPAWNCHIMERA has been compiled as a Position Independent Executable (PIE) to use a third-party library for injection.

T1690
Prevent Command History Logging
MalwareSPAWNCHIMERA

SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.