Cybercriminals linked to China have targeted government entities with the BRICKSTORM malware
Articles by the same author:
1
2
3
4
U.S. and Canadian authorities issued an alert on December 4, 2025, about a campaign conducted by cybercriminals affiliated with China, using the BRICKSTORM malware to target government entities. CISA and the Canadian Centre for Cyber Security, the U.S. and Canadian equivalents of France’s ANSSI, released this security advisory in collaboration with the U.S. National Security Agency (NSA).
The document is based on the analysis of eight samples collected from organizations victimized by this “sophisticated and stealthy malware.” The cybercriminals primarily targeted VMware vSphere and Windows environments, where they were able to create virtual machines. BRICKSTORM enabled them to “browse, download, create, delete, and manipulate files,” as well as perform lateral movement.
The malware includes a “self-monitoring” feature that allows it to reinstall or automatically restart itself in the event of disruptions, making it particularly formidable.