INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

VerdantBamboo Deploys BSD Variant of BRICKSTORM

| 2026-06-08 10:27 LOW HIGH
Executive Summary AI-generated
The China-nexus cyber espionage group has been observed deploying a BSD variant of the known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET and AGENTPSD to target Linux systems. This malicious activity is attributed to VerdantBamboo, a threat cluster that overlaps with hacking groups such as Clay Typhoon, UNC5221, and Warp Panda. The group's use of interactive shell, remote command execution, file manipulation, and command-and-control server switching capabilities makes it a significant threat to organizations worldwide.
Technical Mitigations AI-generated
• Implement a secure patching and updating strategy for Linux systems to prevent exploitation of local privilege escalation flaws. • Use IP address management best practices, such as using virtual private networks (VPNs) or domain name system (DNS) filtering, to limit exposure to VerdantBamboo's proxying capabilities. • Conduct regular security audits and vulnerability assessments on Linux appliances to identify potential entry points for malware deployment.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BRICKSTORMBRICKSTORM CVE-2026-22769CVE-2026-22769
Target & Sectors
Global Scope
Incident Timeline
‎mid-2024
Threat actors used a BSD variant of BRICKSTORM to deploy an agent on Linux appliances.
source_region China
vulnerability CVE-2026-22769
tactic T1059.006 - Python
organisation Virtual Machines
organisation CVSS
‎September 2025
The threat actors used a BSD variant of BRICKSTORM to deploy on compromised Linux appliances.
malware BRICKSTORM
tactic Privilege Escalation
organisation Egnyte Storage Sync
‎March 2026
VerdantBamboo used the BSD variant of BRICKSTORM malware to breach a NAS appliance over SSH.
infrastructure 13.13
organisation Storage Sync
general_metric 13.13 Sync version
organisation Managed Services Provider
organisation MSP
organisation SSH
organisation AOT
organisation Microsoft 365
organisation Conditional Access
organisation a Synology Network Attached Storage
organisation NAS
organisation EDR
‎2026/06/01
Threat actors used IP addresses assigned through the victim organization's web SSL VPN to target VerdantBamboo on Linux appliances.
organisation IP
organisation SSL VPN
‎Jun 08, 2026
The China-nexus cyber espionage group deployed a BSD variant of BRICKSTORM, PLENET and AGENTPSD malware to target Linux systems.
infrastructure Linux
organisation Cyber Espionage /
organisation BSD
organisation PLENET
organisation GRIMBOLT
organisation AGENTPSD
organisation Volexity
organisation VerdantBamboo
organisation Microsoft
organisation Google
organisation CrowdStrike
‎2026/06/08
Linux systems were compromised by deploying a BSD variant of BRICKSTORM.
infrastructure Linux
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎13.13
Software Version
Metrics
infrastructure
‎Microsoft 365
Affected Product
Intelligence Sources