ATT&CKReferencesGoogle BRICKSTORM September 2025

Google BRICKSTORM September 2025

Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen. (2025, September 24). Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareBRICKSTORM

BRICKSTORM has utilized Go libraries to include Garble to obfuscate code.

T1036.005
Match Legitimate Resource Name or Location
MalwareBRICKSTORM

BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`.

T1041
Exfiltration Over C2 Channel
MalwareBRICKSTORM

BRICKSTORM has uploaded files from the victim system to C2 servers.

T1071.001
Web Protocols
MalwareBRICKSTORM

BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers. BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls.

T1083
File and Directory Discovery
MalwareBRICKSTORM

BRICKSTORM has identified specific files and directories within targeted hosts and systems for modification, execution, collection and exfiltration.

T1090.001
Internal Proxy
MalwareBRICKSTORM

BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic.

T1102
Web Service
MalwareBRICKSTORM

BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications.

T1105
Ingress Tool Transfer
MalwareBRICKSTORM

BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.

T1140
Deobfuscate/Decode Files or Information
MalwareBRICKSTORM

BRICKSTORM has decoded its encrypted C2 traffic prior to execution. BRICKSTORM also has the ability to decode its obfuscated payload before execution.

T1568
Dynamic Resolution
MalwareBRICKSTORM

BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses.

T1572
Protocol Tunneling
MalwareBRICKSTORM

BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket.

T1678
Delay Execution
MalwareBRICKSTORM

BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.