CISA, NSA Alert on BRICKSTORM Malware Targeting VMware ESXi and Windows Systems
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), in collaboration with Canadian cyber authorities, have issued a joint alert regarding a sophisticated malware campaign identified as "BRICKSTORM."
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), in collaboration with Canadian cyber authorities, have issued a joint alert regarding a sophisticated malware campaign identified as "BRICKSTORM."
According to the advisory released , state-sponsored actors from the People's Republic of China (PRC) are deploying this tool to infiltrate critical government and technology networks.
The alert characterizes BRICKSTORM as a "backdoor," a type of malicious software that allows attackers to regain access to a compromised system at will. The malware targets VMware vSphere, a software platform for managing virtual servers, and standard Windows environments.
The primary objective of the campaign is espionage. By compromising the software used to manage corporate servers, specifically VMware vCenter and ESXi, attackers are able to covertly monitor activity, extract sensitive data, and clone entire server snapshots to obtain passwords and cryptographic keys without detection.
The report details that these attacks are meticulously planned. In one documented instance, attackers infiltrated a network in April 2024 and remained undetected until September 2025.
The alert characterizes BRICKSTORM as a "backdoor," a type of malicious software that allows attackers to regain access to a compromised system at will.
Initially, access was gained through a vulnerable web server, followed by lateral movement within the network using stolen credentials. The BRICKSTORM malware was then deployed.
BRICKSTORM is challenging to detect due to its ability to blend in with regular network traffic. It employs complex encryption to obscure its communications, making it appear as normal business activities to network defenders.
Additionally, BRICKSTORM features a self-recovery mechanism; if an attempt is made to remove it, the malware can automatically reinstall itself to maintain access.
The targeted sectors include "Government Services and Facilities" and the "Information Technology" sectors. Successful infections can have severe consequences, such as the theft of critical digital keys, enabling attackers to impersonate legitimate users and access restricted network areas.
CISA and NSA recommend that organizations, particularly those in critical infrastructure, actively search for signs of this threat. The agencies have provided technical signatures to help detect the malware.
Administrators are urged to update VMware products promptly, enforce strict access controls to management systems, and monitor for unusual account activity. The alert emphasizes that removing the initial infection may not suffice if attackers have entrenched themselves within virtualization infrastructure.
Based on reporting by GBHackers.
