discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

Volexity says China-linked VerdantBamboo used a BSD variant of BRICKSTORM and other implants to hit Linux appliances, a victim's M365, and an MSP firewall. The group leaned on stolen credentials and appliance abuse to stay hidden.

By Ravie Lakshmanan·Jun 8·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
Image: thehackernews.com

Volexity describes VerdantBamboo as a sophisticated China-nexus cluster that targeted proprietary Linux appliances, a managed services provider, and Microsoft 365. The campaign combined credential theft, firewall/VPN abuse, and custom malware to move across environments without drawing attention.

Why it matters

This matters because it shows attackers continuing to treat Linux appliances and MSP infrastructure as high-value footholds, especially where EDR is absent or limited. It also shows how compromise of one provider can cascade into a victim organization and cloud services.

This story is about burglars who used a back door in a computer box to sneak into a company. They then moved from one machine to another, like hopping across rooftops, and used stolen keys to keep going unnoticed.

Analysis

What Volexity found

Volexity says it uncovered the intrusion during incident response work in September 2025. The target was an unnamed organization whose Egnyte Storage Sync system had been compromised through a local privilege escalation flaw, which the company later fixed in Storage Sync 13.13 in March 2026.

According to the researchers, VerdantBamboo repeatedly accessed the appliance from IP addresses tied to the victim organization’s web SSL VPN. From there, the group used BRICKSTORM’s proxying abilities together with stolen credentials to reach the victim’s Microsoft 365 environment. Volexity says this likely helped the attackers blend into normal traffic and avoid Conditional Access controls.

A broader foothold

After initial cleanup, the same group reportedly returned using stolen administrative credentials to reach the firewall, reconfigure SSL VPN access, and move laterally to other systems. That activity led to malware deployment on a Synology NAS appliance over SSH.

The payloads included PLENET, also called GRIMBOLT, a .NET Core backdoor, and a newer BRICKSTORM build compiled with native ahead-of-time compilation. Volexity says PLENET supports interactive shell access, remote command execution, file changes, and switching command-and-control servers. A second implant, AGENTPSD, is described as a Python-based reverse shell that may act as a fallback.

MSP compromise

Volexity also says the victim’s managed services provider was compromised around the same time, including infection of its pfSense firewall with a BSD variant of BRICKSTORM. The company believes the victim may have been reached through that MSP breach.

Volexity characterizes VerdantBamboo as highly skilled at abusing devices that cannot easily run endpoint detection software. The group also appears to use limited infrastructure per victim and custom implant naming and persistence, which points to deliberate operational security.

Key points

  • VerdantBamboo is described as a China-nexus cluster overlapping with Clay Typhoon, UNC5221, and Warp Panda.
  • Volexity says the group used a BSD variant of BRICKSTORM against a pfSense firewall and other Linux appliances.
  • The victim's Egnyte Storage Sync system was compromised through a local privilege escalation flaw fixed in Storage Sync 13.13.
  • Attackers used proxying and stolen credentials to reach Microsoft 365 and later deployed PLENET and AGENTPSD on a Synology NAS.
  • Volexity says the group likely compromised the victim through its managed services provider.
The Upside

The reporting gives defenders concrete signs to hunt for, including appliance abuse, unusual VPN access, and custom BRICKSTORM variants. The Egnyte flaw was fixed in version 13.13, and the case may help other organizations harden similar devices and MSP links before they are abused.

The Downside

The campaign suggests attackers can keep returning even after cleanup if stolen credentials, firewall access, or MSP trust relationships remain exposed. It also shows that appliances without EDR can become durable footholds for espionage operations, making detection and removal harder.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritychinalinuxmalwarecyber-espionageappliances

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 8, 2026

Source

thehackernews.com

Share

Topics

securitychinalinuxmalwarecyber-espionageappliances

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…