A China-nexus espionage group tracked as UNC5221 has spent years quietly inside US software companies, SaaS providers and law firms. On September 24, 2025, Google’s Mandiant and Threat Intelligence Group published details of the campaign and its main tool, a backdoor called BRICKSTORM. The headline number: victims were compromised for an average of 393 days before anyone noticed.
The campaign matters beyond the organizations directly hit. These attackers were not after ransom. They wanted source code, the email of people who handle sensitive matters, and footholds that could lead into the customers of the companies they breached. For any business that relies on software vendors, cloud platforms or outside counsel, that makes this a supply-chain problem as much as a threat-intelligence story.
What Google found
According to Google, Mandiant had been responding to BRICKSTORM intrusions in the United States since March 2025, and the long dwell times meant many of those compromises began well before that. Targets included US legal services firms, SaaS providers, business process outsourcers and technology companies. Google assessed the actor as suspected China-nexus and noted that US government reporting had linked related activity to other China-based clusters, while saying it lacked enough evidence on its own to confirm those links.
The intruders’ objectives, as Google described them, fell into three groups:
- Source code and intellectual property from software and SaaS companies, which Google assessed was likely used to find new vulnerabilities and develop zero-day exploits against those products.
- Email of key individuals, including developers, system administrators and people working on matters of economic and national-security interest to China, such as trade and legal cases.
- Access to downstream customers, by using a SaaS provider’s environment as a stepping stone into the organizations that depend on it.
How BRICKSTORM stays hidden
BRICKSTORM is not primarily an EDR-evasion trick. Its main advantage is where it lives. The attackers deploy it on systems that typically cannot run endpoint detection agents at all: Linux and BSD-based network and security appliances, and VMware vCenter and ESXi virtualization hosts. Those devices produce little security telemetry, are rarely included in threat hunts, and are often managed by a different team from the one watching the SOC console.
Documented initial access included exploitation of Ivanti Connect Secure VPN vulnerabilities (CVE-2023-46805 and CVE-2024-21887); in other cases the entry point could not be determined because logs had aged out long before discovery. Once in, the actors moved to vCenter, used a malicious Java servlet filter Google calls BRICKSTEAL to capture administrator credentials, and cloned virtual machines such as domain controllers and password vaults so they could extract secrets offline without touching the running systems. To read the email of key people, they used Microsoft Entra ID enterprise applications granted permissions that allow access to any mailbox. Google found no reuse of command-and-control domains across victims, so indicators from one intrusion are of little use in hunting for another.
That combination explains the 393-day dwell time. Nothing about it depends on exotic malware; it depends on defenders not watching their infrastructure layer.
Why software, SaaS and legal are the targets
Software developers hold the code that thousands of other organizations run. Stealing it lets an attacker study it for flaws at leisure and then exploit every customer at once.
SaaS providers hold integrations, tokens and administrative access into their customers’ environments. One compromised provider can be a key to many doors, the same pattern behind the OAuth-token attacks we describe in SaaS supply chain and OAuth attacks.
Law firms hold litigation strategy, merger negotiations, trade disputes and regulatory filings for many clients, often with lighter security than those clients. For an intelligence service, a single firm can offer insight into dozens of companies and government matters.
This is strategic espionage rather than cybercrime. The damage may not be visible for years, when a stolen negotiating position or a zero-day built from stolen code finally gets used. We look at this broader pattern in Espionage in the digital era is hiding in plain sight.
What defenders should do now
- Inventory every appliance and hypervisor. List VPNs, firewalls, load balancers, email gateways and VMware hosts, with firmware versions and who owns them. You cannot hunt on systems you have not listed.
- Run Google’s scanner. Google released an open-source BRICKSTORM scanner for Linux and BSD systems, along with indicators and YARA rules. It will not catch every variant, but it is a fast first check.
- Get appliance and vCenter logs off the device. Forward them to a central log platform with long retention, at least a year given the dwell times involved, and alert on administrative logins, new VM clones and unexpected outbound connections.
- Isolate management interfaces. vCenter, ESXi and appliance admin consoles should be reachable only from a dedicated management network or jump host with phishing-resistant MFA, never from the general network or internet.
- Patch edge devices within days. Treat vulnerabilities in VPNs and remote-access appliances listed in CISA’s Known Exploited Vulnerabilities catalog as emergencies.
- Audit Entra ID and Microsoft 365 app permissions. Review enterprise applications with organization-wide mail access and remove any that are unexplained or unnecessary.
- Ask your vendors and law firms. Add questions about appliance monitoring, log retention and incident notification to vendor reviews and outside counsel guidelines.
For boards, the key message is that a clean EDR dashboard does not mean a clean network. Our cybersecurity compliance and regulatory services include threat-informed reviews of exactly these blind spots.
Update (September 2026): In December 2025 CISA, the NSA and the Canadian Centre for Cyber Security issued a joint analysis report attributing BRICKSTORM to People’s Republic of China state-sponsored actors and warning of ongoing use against VMware vSphere and Windows environments in government and IT-sector organizations. The defensive steps above remain the recommended starting point.
Frequently asked questions
We are not a software company or law firm. Should we care?
Yes, if you use SaaS products or outside counsel, which nearly everyone does. You inherit some of your providers’ risk. And the core technique, hiding on appliances and hypervisors that lack monitoring, works against any organization.
Would our EDR have detected BRICKSTORM?
Probably not, because EDR agents generally do not run on the appliances and virtualization hosts where it was deployed. Detection depends on log collection and hunting at the infrastructure layer.
How long should we keep logs?
With average dwell times above a year, keep security-relevant logs from edge devices, identity systems and virtualization platforms for at least 12 months, and longer if storage allows. Short retention was one reason investigators could not identify the initial access in some cases.
Closing the blind spots
Delana Technologies helps organizations find and monitor the systems attackers hide on, from edge appliances and hypervisors to SaaS integrations, and build vendor oversight that accounts for nation-state risk. To assess your exposure, call 239.414.5126 or contact us.
Sources: Google Threat Intelligence Group and Mandiant, “Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors” (September 24, 2025); The Hacker News and SecurityWeek coverage of the report; CISA, NSA and Canadian Centre for Cyber Security, BRICKSTORM Backdoor analysis report AR25-338A (December 2025); CISA Known Exploited Vulnerabilities catalog.
