CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise IT Services & Support in Houston, TX
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Managed Service Provider Houston Cybersecurity
Shane Stevens
Shane Stevens September 25th, 2025

BrickStorm Backdoor: Chinese State-Sponsored Hackers Maintain Year-Long Access to U.S. Companies

Sophisticated Cyberespionage Campaign Targets Systems Without Endpoint Protection – Extended Threat Persistence Demonstrates Need For Proactive Detection Capabilities

Cybersecurity Alert
The BrickStorm backdoor sat inside U.S. companies for 393 days before anyone found it. The gear it hides in is the gear nobody watches.

China-nexus hackers used BrickStorm to live in edge appliances and VMware servers for over a year. Here is why a small Houston business in someone else's supply chain is squarely in the blast radius.

TL;DR
BrickStorm is a stealthy backdoor that Google Threat Intelligence Group ties to the China-nexus group UNC5221. It hides in network appliances and VMware vCenter/ESXi hosts - systems that do not run normal endpoint security - and stayed undetected for an average of 393 days. The targets were legal firms, SaaS providers, and outsourcers, chosen because they are doorways into other companies. For a Houston SMB, the lesson is not "we are too small." It is that your vendors, and the gear you never log, are the exposure.
🧱 What BrickStorm Is 👁️ Why It Stayed Hidden 393 Days 🔗 Why an SMB Is in the Blast Radius 🚀 How CinchOps Helps

The BrickStorm backdoor is a Go-based espionage tool that China-nexus hackers plant in network appliances and virtualization servers, and it matters to a Houston small business because it proved attackers can live undetected in the exact gear most companies never monitor - for an average of 393 days.

In September 2025, Google Threat Intelligence Group and Mandiant published what they had been chasing since March: a quiet, patient campaign that had been reading U.S. companies' mail for more than a year without tripping a single alarm. The tool was BrickStorm. The group was UNC5221, a suspected China-nexus actor. And the reason it worked is uncomfortable - the attackers deliberately picked systems that do not run the antivirus and detection software everyone relies on.

Most owners read a headline like that and file it under "big-company problem." That is the wrong file. This campaign hit legal firms, software-as-a-service providers, and business process outsourcers on purpose, because those companies hold the keys to hundreds of downstream clients. If you are a small Houston business that trusts a SaaS platform or an outsourced back office, you are not outside this story. You are one of the reasons it was profitable.

The core idea: BrickStorm did not beat anyone's firewall by force. It walked into the one room nobody had a camera in - the appliances and virtualization layer - and waited. The fix is not a bigger firewall. It is seeing the gear you forgot you had.

What Is the BrickStorm Backdoor?

A Go-based backdoor built to hide in appliances and virtualization gear, not laptops.

BrickStorm is a backdoor written in the Go language that gives an attacker a hidden foothold on network edge devices and VMware infrastructure, where it can move files, run commands, and tunnel traffic while looking like normal system activity.

Strip away the jargon and BrickStorm is a set of keys the intruder cuts for themselves and hides in a lock nobody checks. According to Mandiant's analysis, it acts as a web server and a tunneling relay, and it carries a specific menu of abilities. Each one is picked to stay quiet:

  • File and directory access. Browse, upload, and download whatever sits on the compromised system.
  • Remote command execution. Run shell commands as if the attacker were logged in at the console.
  • SOCKS proxy tunneling. Route the attacker's traffic through your network so it blends in with legitimate connections.
  • Encrypted command-and-control. Talk to the attacker over channels that look like ordinary encrypted web traffic.
  • Per-victim infrastructure. A different control setup for each target, so defenders cannot pattern-match one victim to the next.

Here is the part that should stick. Mandiant reports the group planted BrickStorm on network appliances - Linux and BSD-based devices from several manufacturers - and then pivoted to VMware vCenter and ESXi hosts. In several cases they installed a malicious Java Servlet filter on vCenter to quietly capture administrator passwords, and cloned entire virtual machines of critical systems like domain controllers to pick through them offline. None of that touches a laptop where your antivirus would notice.

BrickStorm targeting of network appliances and VMware infrastructure
BrickStorm deliberately targets edge appliances and virtualization infrastructure that lack traditional endpoint protection. Source: Google Cloud (Mandiant / GTIG).

In 35 years around IT, the systems that bite businesses are almost never the ones on the security dashboard. They are the firewall in the closet, the VPN appliance nobody has patched since it was installed, the virtualization host that "just works." BrickStorm is a masterclass in that truth. It lives exactly where the visibility ends.

Why Did BrickStorm Stay Hidden for 393 Days?

Because the gear it chose has no endpoint agent, and the logs run out before anyone looks.

BrickStorm stayed hidden for an average of 393 days because it lived on appliances and virtualization hosts that cannot run endpoint detection tools, and by the time it was found, the logs that would have shown the break-in had already been overwritten.

The 393-day figure comes straight from Mandiant, and it is not a typo. That is more than a year of an intruder reading email, copying documents, and watching how a company operates. Two design choices made that dwell time possible, and both should reshape how a Houston SMB thinks about "coverage."

First, no agent, no alert. The endpoint detection tools that catch malware on your PCs and servers simply do not install on a VPN concentrator or an ESXi host. Those systems are closed appliances. So when BrickStorm ran there, nothing was watching. Second, the trail went cold on its own. Mandiant noted the average dwell time exceeded most companies' log retention, meaning the evidence of the original break-in had aged out before defenders even knew to look. The attackers also took care to erase their tracks, which is why the initial way in often could not be pinned down at all. In at least one case they exploited a flaw in an Ivanti Connect Secure edge device, but for many victims the entry point stayed a mystery.

THE 393-DAY BLIND SPOT Why a backdoor can live over a year without one alert DAY 0 Break-in via edge appliance LOGS EXPIRE Evidence of entry overwritten DAY 393 Average discovery (Mandiant) More than a year of silent data theft, no alarm raised WHERE YOUR SECURITY TOOLS CAN SEE ✓ Laptops and servers Endpoint detection runs here. Alerts fire. ✗ Edge appliances and VMware layer No agent installs here. BrickStorm lived here. You cannot detect a break-in in a place you are not watching. Coverage gaps are the whole attack. CinchOps · cinchops.com
Two design choices - agentless target gear and dwell time longer than log retention - are what let BrickStorm hide for an average of 393 days.
Asset inventory of network devices during BrickStorm incident response
A full asset inventory is the first step to closing the visibility gap - you cannot monitor a device you do not know you have. Source: Google Cloud (Mandiant / GTIG).

The takeaway is not "buy another tool." It is that a security program with a blind spot the size of your virtualization layer is not a security program. If a device on your network cannot run detection software, it needs a different form of watching - centralized logs, network monitoring, and someone actually reviewing them. Otherwise it is a room with no camera, and BrickStorm showed exactly what patient attackers do with a room like that.

Everybody guards the front door and forgets the utility closet. BrickStorm did not pick a lock - it moved into the appliance nobody was logging and waited a year. The businesses that get burned are not the ones without a firewall. They are the ones who cannot tell you what is running on the box in the corner, or the last time anyone looked at it.
Shane Stevens, CEO, CinchOps - LinkedIn

Why Is a Small Houston Business in the Blast Radius?

Because the targets were chosen as doorways into everyone they serve.

A small Houston business is exposed to a campaign like BrickStorm even without being a direct target, because the hackers deliberately hit legal firms, SaaS platforms, and outsourcers - the vendors that hold data and access for hundreds of smaller companies downstream.

Look at who UNC5221 went after. Mandiant lists legal services, software-as-a-service providers, business process outsourcers, and technology companies. That is not a random spread. Those four categories share one trait: each one is a hub with spokes running to many other businesses. Compromise one SaaS provider and you potentially reach every client on the platform. That is the whole appeal of a supply-chain target, and it is why "we are too small to matter" is the wrong way to read this.

Bring it home to Houston. This region runs on exactly the industries that sit in these supply chains. A law firm in the Galleria holds merger and litigation files for dozens of local companies. An oil and gas operator or energy services vendor connects into partners across the Gulf Coast and handles data that a foreign intelligence service genuinely wants. A CPA practice in Sugar Land or an engineering firm in Katy is a trusted node for its clients. When an attacker wants strategic intelligence, these mid-market firms are not too small - they are the efficient path in.

So the question for a small business is not "am I important enough for China to target?" It is "whose network am I connected to, and who is connected to mine?" The right response is not paranoia. It is basic hygiene applied to relationships you already have: know your critical vendors, ask what they do about exactly this class of threat, and make sure a compromise on their side cannot walk straight into yours. That last part - segmentation and access limits between you and your partners - is ordinary cybersecurity hygiene, and it is what turns "our vendor got breached" into an inconvenience instead of a disaster.

Not sure what is running on your edge and virtualization gear?

Most SMBs cannot name every appliance on their network or the last time it was patched. That inventory gap is where threats like BrickStorm live. A CinchOps assessment finds the blind spots before someone else does.

Explore CinchOps cybersecurity →

One more point, because it is the practical one. Mandiant released a free scanner so organizations can check their own appliances for BrickStorm. That tool is useful, but a single scan is a snapshot. The businesses that stay safe are not the ones who ran a scan once - they are the ones who fixed the underlying gap so the next backdoor, with a different name, has nowhere quiet to sit.

See the Gear Your Security Tools Cannot

BrickStorm won by hiding where endpoint tools do not reach. CinchOps closes that gap for Houston-area SMBs - inventorying every appliance and virtualization host, centralizing logs from devices that cannot run an agent, and watching the whole network, not just the laptops. It is part of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Helps Your Business

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. BrickStorm is a reminder that real protection has to cover the whole network, not just the machines that happen to run an antivirus. For a Houston SMB, that means closing the blind spots this campaign exploited:

  • Full asset inventory. We find every appliance and virtualization host on your network, so nothing sits unwatched in a closet.
  • Monitoring beyond the endpoint. Centralized logging and network monitoring for the edge and VMware gear that cannot run a detection agent.
  • Patching the perimeter. Edge devices like VPN appliances get updated on schedule, closing the doors attackers use for initial access.
  • Vendor and access review. We help you segment partner connections so a supplier's breach does not become yours.

CinchOps serves businesses across Houston, Katy, and Sugar Land, with industry experience in law firms, oil and gas, and engineering firms - the supply-chain nodes campaigns like this one target most.

You do not have to be a Fortune 500 to be worth a year of a state actor's attention. You have to be connected to one. If you cannot say for certain what is running on your network gear or who can reach it, that is the place to start. Talk to CinchOps and let us map the blind spots before someone else moves into them.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What is the BrickStorm backdoor?

BrickStorm is a Go-based backdoor that Google Threat Intelligence Group attributes to the China-nexus group UNC5221. It hides on network appliances and VMware vCenter and ESXi hosts, where it can browse files, run commands, and tunnel traffic. Because it targets gear that does not run endpoint security, it evaded detection for an average of 393 days.

Why should a small Houston business care about BrickStorm?

The campaign targeted legal firms, SaaS providers, and outsourcers because they are doorways into hundreds of downstream companies. A small Houston business connected to those vendors sits in the blast radius. Houston's concentration of legal, energy, and engineering firms makes the region a natural supply-chain target for state-sponsored intelligence gathering.

How can a business check for and defend against BrickStorm?

Mandiant released a free scanner script for appliances, which is a good first check. Lasting defense means inventorying every network device, centralizing logs from gear that cannot run a detection agent, patching edge appliances like VPN devices, and monitoring the virtualization layer. The goal is removing the blind spot BrickStorm exploited, not just running one scan.

Discover More

CinchOps Cybersecurity Services
CinchOps Managed IT Services
What Is MDR and Why SMBs Need It
The Role of Patch Management
Security Awareness Training for SMBs
IT & Security for Law Firms

Sources

  • Google Cloud / Mandiant, Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors (393-day dwell time, UNC5221, VMware targeting)
  • Mandiant, BRICKSTORM Scanner (free detection script for appliances)
  • The Hacker News, UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors
  • BleepingComputer, Google: Brickstorm malware used to steal U.S. orgs' data for over a year
  • The Hacker News, CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

August 4th, 2026
Houston Cybersecurity
Data Breach Cost by Industry: 2024 to 2026 Trends

A Sector By Sector View Of IBM’s 2026 Findings – What Changed For Energy, Industrial And Financial Services

June 8th, 2026
Cybersecurity Houston
Cybersecurity in Katy: Reading May 2026’s Ransomware Numbers

661 Ransomware Attacks In One Month: What Katy Should Know

May 28th, 2026
Managed IT Houston
Houston Small Business IT Mistakes: 5 Patterns That Cost Companies Real Money

Five IT Patterns That Cost Houston Companies Money – The Silent IT Mistakes Breaking Houston Businesses

August 24th, 2026
Managed IT Houston
How to Choose an IT Services Provider in Houston

Price The Hire At Total Cost, Not Salary – Under 50 People, You Do Not Need A Full-Time IT Employee

January 2nd, 2026
Managed Service Provider Houston
7 Essential Business Continuity Strategies for Houston SMBs

From Hurricanes to Hackers: A 7-Step Plan to Keep Your Houston Business Running

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery
  • Cloud Services
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy