I Need IT Support Now
Managed Service Provider Houston Cybersecurity
Shane

BrickStorm Backdoor: Chinese State-Sponsored Hackers Maintain Year-Long Access to U.S. Companies

Sophisticated Cyberespionage Campaign Targets Systems Without Endpoint Protection – Extended Threat Persistence Demonstrates Need For Proactive Detection Capabilities

Cybersecurity Alert
The BrickStorm backdoor sat inside U.S. companies for 393 days before anyone found it. The gear it hides in is the gear nobody watches.

China-nexus hackers used BrickStorm to live in edge appliances and VMware servers for over a year. Here is why a small Houston business in someone else's supply chain is squarely in the blast radius.

TL;DR
BrickStorm is a stealthy backdoor that Google Threat Intelligence Group ties to the China-nexus group UNC5221. It hides in network appliances and VMware vCenter/ESXi hosts - systems that do not run normal endpoint security - and stayed undetected for an average of 393 days. The targets were legal firms, SaaS providers, and outsourcers, chosen because they are doorways into other companies. For a Houston SMB, the lesson is not "we are too small." It is that your vendors, and the gear you never log, are the exposure.

The BrickStorm backdoor is a Go-based espionage tool that China-nexus hackers plant in network appliances and virtualization servers, and it matters to a Houston small business because it proved attackers can live undetected in the exact gear most companies never monitor - for an average of 393 days.

In September 2025, Google Threat Intelligence Group and Mandiant published what they had been chasing since March: a quiet, patient campaign that had been reading U.S. companies' mail for more than a year without tripping a single alarm. The tool was BrickStorm. The group was UNC5221, a suspected China-nexus actor. And the reason it worked is uncomfortable - the attackers deliberately picked systems that do not run the antivirus and detection software everyone relies on.

Most owners read a headline like that and file it under "big-company problem." That is the wrong file. This campaign hit legal firms, software-as-a-service providers, and business process outsourcers on purpose, because those companies hold the keys to hundreds of downstream clients. If you are a small Houston business that trusts a SaaS platform or an outsourced back office, you are not outside this story. You are one of the reasons it was profitable.

The core idea: BrickStorm did not beat anyone's firewall by force. It walked into the one room nobody had a camera in - the appliances and virtualization layer - and waited. The fix is not a bigger firewall. It is seeing the gear you forgot you had.

What Is the BrickStorm Backdoor?

A Go-based backdoor built to hide in appliances and virtualization gear, not laptops.

BrickStorm is a backdoor written in the Go language that gives an attacker a hidden foothold on network edge devices and VMware infrastructure, where it can move files, run commands, and tunnel traffic while looking like normal system activity.

Strip away the jargon and BrickStorm is a set of keys the intruder cuts for themselves and hides in a lock nobody checks. According to Mandiant's analysis, it acts as a web server and a tunneling relay, and it carries a specific menu of abilities. Each one is picked to stay quiet:

  • File and directory access. Browse, upload, and download whatever sits on the compromised system.
  • Remote command execution. Run shell commands as if the attacker were logged in at the console.
  • SOCKS proxy tunneling. Route the attacker's traffic through your network so it blends in with legitimate connections.
  • Encrypted command-and-control. Talk to the attacker over channels that look like ordinary encrypted web traffic.
  • Per-victim infrastructure. A different control setup for each target, so defenders cannot pattern-match one victim to the next.

Here is the part that should stick. Mandiant reports the group planted BrickStorm on network appliances - Linux and BSD-based devices from several manufacturers - and then pivoted to VMware vCenter and ESXi hosts. In several cases they installed a malicious Java Servlet filter on vCenter to quietly capture administrator passwords, and cloned entire virtual machines of critical systems like domain controllers to pick through them offline. None of that touches a laptop where your antivirus would notice.

BrickStorm targeting of network appliances and VMware infrastructure
BrickStorm deliberately targets edge appliances and virtualization infrastructure that lack traditional endpoint protection. Source: Google Cloud (Mandiant / GTIG).

In 35 years around IT, the systems that bite businesses are almost never the ones on the security dashboard. They are the firewall in the closet, the VPN appliance nobody has patched since it was installed, the virtualization host that "just works." BrickStorm is a masterclass in that truth. It lives exactly where the visibility ends.

Why Did BrickStorm Stay Hidden for 393 Days?

Because the gear it chose has no endpoint agent, and the logs run out before anyone looks.

BrickStorm stayed hidden for an average of 393 days because it lived on appliances and virtualization hosts that cannot run endpoint detection tools, and by the time it was found, the logs that would have shown the break-in had already been overwritten.

The 393-day figure comes straight from Mandiant, and it is not a typo. That is more than a year of an intruder reading email, copying documents, and watching how a company operates. Two design choices made that dwell time possible, and both should reshape how a Houston SMB thinks about "coverage."

First, no agent, no alert. The endpoint detection tools that catch malware on your PCs and servers simply do not install on a VPN concentrator or an ESXi host. Those systems are closed appliances. So when BrickStorm ran there, nothing was watching. Second, the trail went cold on its own. Mandiant noted the average dwell time exceeded most companies' log retention, meaning the evidence of the original break-in had aged out before defenders even knew to look. The attackers also took care to erase their tracks, which is why the initial way in often could not be pinned down at all. In at least one case they exploited a flaw in an Ivanti Connect Secure edge device, but for many victims the entry point stayed a mystery.

THE 393-DAY BLIND SPOT Why a backdoor can live over a year without one alert DAY 0 Break-in via edge appliance LOGS EXPIRE Evidence of entry overwritten DAY 393 Average discovery (Mandiant) More than a year of silent data theft, no alarm raised WHERE YOUR SECURITY TOOLS CAN SEE Laptops and servers Endpoint detection runs here. Alerts fire. Edge appliances and VMware layer No agent installs here. BrickStorm lived here. You cannot detect a break-in in a place you are not watching. Coverage gaps are the whole attack. CinchOps · cinchops.com
Two design choices - agentless target gear and dwell time longer than log retention - are what let BrickStorm hide for an average of 393 days.
Asset inventory of network devices during BrickStorm incident response
A full asset inventory is the first step to closing the visibility gap - you cannot monitor a device you do not know you have. Source: Google Cloud (Mandiant / GTIG).

The takeaway is not "buy another tool." It is that a security program with a blind spot the size of your virtualization layer is not a security program. If a device on your network cannot run detection software, it needs a different form of watching - centralized logs, network monitoring, and someone actually reviewing them. Otherwise it is a room with no camera, and BrickStorm showed exactly what patient attackers do with a room like that.

Everybody guards the front door and forgets the utility closet. BrickStorm did not pick a lock - it moved into the appliance nobody was logging and waited a year. The businesses that get burned are not the ones without a firewall. They are the ones who cannot tell you what is running on the box in the corner, or the last time anyone looked at it.
Shane Stevens, CEO, CinchOps - LinkedIn

Why Is a Small Houston Business in the Blast Radius?

Because the targets were chosen as doorways into everyone they serve.

A small Houston business is exposed to a campaign like BrickStorm even without being a direct target, because the hackers deliberately hit legal firms, SaaS platforms, and outsourcers - the vendors that hold data and access for hundreds of smaller companies downstream.

Look at who UNC5221 went after. Mandiant lists legal services, software-as-a-service providers, business process outsourcers, and technology companies. That is not a random spread. Those four categories share one trait: each one is a hub with spokes running to many other businesses. Compromise one SaaS provider and you potentially reach every client on the platform. That is the whole appeal of a supply-chain target, and it is why "we are too small to matter" is the wrong way to read this.

Bring it home to Houston. This region runs on exactly the industries that sit in these supply chains. A law firm in the Galleria holds merger and litigation files for dozens of local companies. An oil and gas operator or energy services vendor connects into partners across the Gulf Coast and handles data that a foreign intelligence service genuinely wants. A CPA practice in Sugar Land or an engineering firm in Katy is a trusted node for its clients. When an attacker wants strategic intelligence, these mid-market firms are not too small - they are the efficient path in.

So the question for a small business is not "am I important enough for China to target?" It is "whose network am I connected to, and who is connected to mine?" The right response is not paranoia. It is basic hygiene applied to relationships you already have: know your critical vendors, ask what they do about exactly this class of threat, and make sure a compromise on their side cannot walk straight into yours. That last part - segmentation and access limits between you and your partners - is ordinary cybersecurity hygiene, and it is what turns "our vendor got breached" into an inconvenience instead of a disaster.

Not sure what is running on your edge and virtualization gear?

Most SMBs cannot name every appliance on their network or the last time it was patched. That inventory gap is where threats like BrickStorm live. A CinchOps assessment finds the blind spots before someone else does.

Explore CinchOps cybersecurity →

One more point, because it is the practical one. Mandiant released a free scanner so organizations can check their own appliances for BrickStorm. That tool is useful, but a single scan is a snapshot. The businesses that stay safe are not the ones who ran a scan once - they are the ones who fixed the underlying gap so the next backdoor, with a different name, has nowhere quiet to sit.

See the Gear Your Security Tools Cannot

BrickStorm won by hiding where endpoint tools do not reach. CinchOps closes that gap for Houston-area SMBs - inventorying every appliance and virtualization host, centralizing logs from devices that cannot run an agent, and watching the whole network, not just the laptops. It is part of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Helps Your Business

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. BrickStorm is a reminder that real protection has to cover the whole network, not just the machines that happen to run an antivirus. For a Houston SMB, that means closing the blind spots this campaign exploited:

  • Full asset inventory. We find every appliance and virtualization host on your network, so nothing sits unwatched in a closet.
  • Monitoring beyond the endpoint. Centralized logging and network monitoring for the edge and VMware gear that cannot run a detection agent.
  • Patching the perimeter. Edge devices like VPN appliances get updated on schedule, closing the doors attackers use for initial access.
  • Vendor and access review. We help you segment partner connections so a supplier's breach does not become yours.

CinchOps serves businesses across Houston, Katy, and Sugar Land, with industry experience in law firms, oil and gas, and engineering firms - the supply-chain nodes campaigns like this one target most.

You do not have to be a Fortune 500 to be worth a year of a state actor's attention. You have to be connected to one. If you cannot say for certain what is running on your network gear or who can reach it, that is the place to start. Talk to CinchOps and let us map the blind spots before someone else moves into them.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What is the BrickStorm backdoor?

BrickStorm is a Go-based backdoor that Google Threat Intelligence Group attributes to the China-nexus group UNC5221. It hides on network appliances and VMware vCenter and ESXi hosts, where it can browse files, run commands, and tunnel traffic. Because it targets gear that does not run endpoint security, it evaded detection for an average of 393 days.

Why should a small Houston business care about BrickStorm?

The campaign targeted legal firms, SaaS providers, and outsourcers because they are doorways into hundreds of downstream companies. A small Houston business connected to those vendors sits in the blast radius. Houston's concentration of legal, energy, and engineering firms makes the region a natural supply-chain target for state-sponsored intelligence gathering.

How can a business check for and defend against BrickStorm?

Mandiant released a free scanner script for appliances, which is a good first check. Lasting defense means inventorying every network device, centralizing logs from gear that cannot run a detection agent, patching edge appliances like VPN devices, and monitoring the virtualization layer. The goal is removing the blind spot BrickStorm exploited, not just running one scan.

Discover More

Sources

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506