VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
Volexity says China-linked VerdantBamboo used a BSD variant of BRICKSTORM and other implants to hit Linux appliances, a victim's M365, and an MSP firewall. The group leaned on stolen credentials and appliance abuse to stay hidden.
Intelligence analysis by GPT-5.4 Mini

Volexity describes VerdantBamboo as a sophisticated China-nexus cluster that targeted proprietary Linux appliances, a managed services provider, and Microsoft 365. The campaign combined credential theft, firewall/VPN abuse, and custom malware to move across environments without drawing attention.
This story is about burglars who used a back door in a computer box to sneak into a company. They then moved from one machine to another, like hopping across rooftops, and used stolen keys to keep going unnoticed.
Analysis
What Volexity found
Volexity says it uncovered the intrusion during incident response work in September 2025. The target was an unnamed organization whose Egnyte Storage Sync system had been compromised through a local privilege escalation flaw, which the company later fixed in Storage Sync 13.13 in March 2026.
According to the researchers, VerdantBamboo repeatedly accessed the appliance from IP addresses tied to the victim organization’s web SSL VPN. From there, the group used BRICKSTORM’s proxying abilities together with stolen credentials to reach the victim’s Microsoft 365 environment. Volexity says this likely helped the attackers blend into normal traffic and avoid Conditional Access controls.
A broader foothold
After initial cleanup, the same group reportedly returned using stolen administrative credentials to reach the firewall, reconfigure SSL VPN access, and move laterally to other systems. That activity led to malware deployment on a Synology NAS appliance over SSH.
The payloads included PLENET, also called GRIMBOLT, a .NET Core backdoor, and a newer BRICKSTORM build compiled with native ahead-of-time compilation. Volexity says PLENET supports interactive shell access, remote command execution, file changes, and switching command-and-control servers. A second implant, AGENTPSD, is described as a Python-based reverse shell that may act as a fallback.
MSP compromise
Volexity also says the victim’s managed services provider was compromised around the same time, including infection of its pfSense firewall with a BSD variant of BRICKSTORM. The company believes the victim may have been reached through that MSP breach.
Volexity characterizes VerdantBamboo as highly skilled at abusing devices that cannot easily run endpoint detection software. The group also appears to use limited infrastructure per victim and custom implant naming and persistence, which points to deliberate operational security.
Key points
- VerdantBamboo is described as a China-nexus cluster overlapping with Clay Typhoon, UNC5221, and Warp Panda.
- Volexity says the group used a BSD variant of BRICKSTORM against a pfSense firewall and other Linux appliances.
- The victim's Egnyte Storage Sync system was compromised through a local privilege escalation flaw fixed in Storage Sync 13.13.
- Attackers used proxying and stolen credentials to reach Microsoft 365 and later deployed PLENET and AGENTPSD on a Synology NAS.
- Volexity says the group likely compromised the victim through its managed services provider.
The reporting gives defenders concrete signs to hunt for, including appliance abuse, unusual VPN access, and custom BRICKSTORM variants. The Egnyte flaw was fixed in version 13.13, and the case may help other organizations harden similar devices and MSP links before they are abused.
The campaign suggests attackers can keep returning even after cleanup if stolen credentials, firewall access, or MSP trust relationships remain exposed. It also shows that appliances without EDR can become durable footholds for espionage operations, making detection and removal harder.



