Panda PRC China
– Getty Images

VMware has attracted more bad news, and this time it has nothing to do with Broadcom.

Instead, a security briefing from The National Security Agency (NSA) revealed bad actors are exploiting a backdoor for VMware vSphere, in particular VMware vCenter servers and VMware ESXI, to grab cloned virtual machine (VM) snapshots for credential extraction and create stealth, rogue VMs.

The Brickstorm campaign, as it is known, is also a minor threat to Windows environments.

Published last week by the NSA in conjunction with the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre for Cyber Security, the briefing claimed attackers last year breached a web server located in one organization’s demilitarized zone (DMZ). Subsequently, the actors were able to move to the domain controller, where they then copied the Active Directory database, gathering credentials for a managed service provider (MSP) account.

“Using the MSP credentials, the cyber actors proceeded to move from the internal domain controller to the VMware vCenter server. From the web server, the actors also moved laterally using Server Message Block (SMB) to two jump servers and an ADFS (Active Directory Federation Services) server, from which they exfiltrated cryptographic keys,” the researchers wrote.

Users were recommended to upgrade all VMware vSphere servers to the latest version and harden the VMware vSphere environments by applying VMware’s official guidance available on GitHub.

Network teams were also encouraged to carry out proper segmentation to restrict network traffic from the DMZ to the internal network, and disable both RDP (Remote Desktop Protocol) and SMB (Server Message Block) protocols from the DMZ to the internal network to prevent unauthorized access. It was also suggested to block unauthorized DNS-over-HTTPS (DoH) providers and external DoH traffic to limit unmonitored communications.

A less-than-warm welcome to Warp Panda

Accused of the wrongdoing were People’s Republic of China (PRC) state-sponsored actors, specifically a group named by CrowdStrike as Warp Panda. China has denied the claims, with a spokesperson for the Chinese embassy in Washington telling Reuters the Chinese government does not “encourage, support or connive at cyberattacks,” and that it rejected the “irresponsible assertion” from the agencies, which had “neither put forward any request related to the issue nor presented any factual evidence.”

With origins dating back to 2022, Brickstorm is a custom executable and linkable format (ELF) backdoor written in the Go programming language, which allows cyber actors to sustain covert access while supporting functions for initial compromise, persistence, and secure command-and-control (C2) operations.

Brickstorm begins by performing system checks and ensuring persistence through a self-monitoring mechanism that automatically reinstalls or restarts when interrupted. Its C2 communications are hidden through multiple layers of encryption, including DNS-over-HTTPS (DoH), and by imitating standard web server behavior to blend with legitimate network traffic.

With interactive shell access on the system, bad actors can browse, upload, download, create, delete, and manipulate files, as well as manoeuvre as a SOCKS proxy to compromise additional systems through lateral movement.

Google Cloud’s Mandiant security division noted an increase in Brickstorm activity in September, followed by Resecurity research pinning an October hack on security firm F5 on Brickstorm malware.

That F5 exploit saw a threat actor breach its networks and gain year-long access to certain areas of its system, giving access to parts of the company’s BIG-IP source code and information about undisclosed vulnerabilities that it had been working on.

Around the same time as the F5 revelation, Cisco was pressed by the U.S. government over a separate exploit in its firewall offerings that may have allowed for a nation-state-backed breach, linked to the China-affiliated ArcaneDoor campaign.

Similarly, a historical Cisco bug was revealed as being exploited by a Russian espionage group, leading to the FBI releasing an urgent briefing over the summer similar to this month’s Brickstorm warning.