UNC5221 BRICKSTORM espionage against U.S. legal and SaaS firms
Case score 57
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 57
- Main story score
- 57
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
- Campaign Core BRICKSTORM espionage campaign with long-dwell access, prior Ivanti exploitation, and confirmed theft of source code and intellectual property. main
Overview
UNC5221 BRICKSTORM espionage campaign against U.S. legal, SaaS, BPO, and technology firms disclosed
Mandiant and Google Threat Intelligence Group described an active China-nexus espionage campaign tracked as UNC5221 that uses the BRICKSTORM backdoor to maintain long-term access to victim organizations, especially U.S. legal services, SaaS providers, Business Process Outsourcers, and technology companies. The operation is linked to prior Ivanti Connect Secure exploitation with CVE-2023-46805 and CVE-2024-21887, has been used against Linux and BSD-based appliances, and includes stealthy persistence, SOCKS proxying, WebSockets command-and-control, and credential theft through the BRICKSTEAL Apache Tomcat servlet filter. Google said the group has responded to several intrusions since March 2025, observed an average dwell time of 393 days, and released a shell script scanner to help identify BRICKSTORM activity on affected systems.