CISA NSA and Canadian Cyber Centre Issue Updated Brickstorm Backdoor Analysis With Rust Variants
CISA, NSA, and the Canadian Centre for Cyber Security on May 3 updated their
The Rust rewrite of Brickstorm, adding encrypted WebSocket C2 and a self-reinstalling persistence mechanism, signals an active development program hardening against detection, not incremental maintenance. The sharpest indicator is the ADFS cryptographic key export: exfiltrated federation keys enable offline token forgery that survives network eviction, so any remediation omitting a full PKI rebuild is incomplete. Whether the Rust variants represent the same PRC team or a separate affiliated cluster borrowing the tooling is unresolved and complicates the advisory's implied threat continuity. Government-channel attribution of a new variant or cluster within the next 90 days carries roughly even odds, as diplomatic and intelligence equities routinely suppress disclosure independent of investigative momentum.
4 sources
- CISA, NSA, and Canadian Cyber Centre update Brickstorm analysis with new Rust-based variants -
Industrial Cyber - CISA, NSA and Cyber Centre Warn Critical Infrastructure of BRICKSTORM Malware Used by People's Republic of China State-Sponsored Actors
- NSA Joins CISA to Release Guidance on Detecting BRICKSTORM Backdoor Activity
- CISA warns of continued threat activity linked to Brickstorm malware -
Cybersecurity Dive