You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
unc5221
About this tag
The tag unc5221 covers a sophisticated backdoor campaign called BRICKSTORM, attributed to Chinese state-sponsored actors. This threat targets VMware vSphere management infrastructure, Windows systems, and enterprise network appliances. The campaign focuses on appliance persistence, credential harvesting, and covert command-and-control for long-term espionage. Defenders are advised to treat exposures to appliance management interfaces and virtualization control planes as high-risk priorities and initiate hunt and remediation workflows immediately.
Chinese state-sponsored actors have been observed deploying a sophisticated backdoor called BRICKSTORM to maintain long-term, stealthy access across public‑sector and information technology environments — with confirmed targeting of VMware vSphere management infrastructure, Windows systems, and...