IC Technology & Surveillance — 2026-05-05

CISA NSA and Canadian Cyber Centre Issue Updated Brickstorm Backdoor Analysis With Rust Variants

CISA, NSA, and the Canadian Centre for Cyber Security on May 3 updated their Brickstorm malware analysis report, adding new indicators of compromise and detection signatures for three additional samples, two of them Rust-based. The Rust variants use encrypted WebSocket C2 and a self-reinstalling background-service mechanism for persistence and defense evasion. CISA's advisory documents a confirmed incident response engagement at a victim organization where PRC state-sponsored actors installed Brickstorm on an internal VMware vCenter server in April 2024. The actors subsequently compromised two domain controllers and an ADFS server, exported cryptographic keys, and maintained access through at least September 3, 2025. The advisory directs vSphere operators to apply current patches, enforce DMZ-to-internal network segmentation, and block unauthorized DNS-over-HTTPS providers.

Analysis
The Rust rewrite of Brickstorm, adding encrypted WebSocket C2 and a self-reinstalling persistence mechanism, signals an active development program hardening against detection, not incremental maintenance. The sharpest indicator is the ADFS cryptographic key export: exfiltrated federation keys enable offline token forgery that survives network eviction, so any remediation omitting a full PKI rebuild is incomplete. Whether the Rust variants represent the same PRC team or a separate affiliated cluster borrowing the tooling is unresolved and complicates the advisory's implied threat continuity. Government-channel attribution of a new variant or cluster within the next 90 days carries roughly even odds, as diplomatic and intelligence equities routinely suppress disclosure independent of investigative momentum.
4 sources
  1. CISA, NSA, and Canadian Cyber Centre update Brickstorm analysis with new Rust-based variants - Industrial Cyber
  2. CISA, NSA and Cyber Centre Warn Critical Infrastructure of BRICKSTORM Malware Used by People's Republic of China State-Sponsored Actors
  3. NSA Joins CISA to Release Guidance on Detecting BRICKSTORM Backdoor Activity
  4. CISA warns of continued threat activity linked to Brickstorm malware - Cybersecurity Dive

View in full brief →

UNCLASSIFIED // OPEN SOURCE