A new long-running intrusion case (shared by Volexity) shows how attackers can turn “enterprise infrastructure” into a stealth tunnel—without triggering the usual external-login alerts. The target wasn’t a typical endpoint. Instead, the attackers (linked to UNC5221 / VerdantBamboo) hid malicious tooling inside boundary and infrastructure devices for extended periods. A key move: implanting the Brickstorm backdoor on a Linux VM running Egnyte Storage Sync. What made it dangerous wasn’t just the access—it was the illusion. By routing activity through proxy-like capabilities and using stolen credentials, the traffic looked like it originated from inside the company network. That helped bypass conditional access controls that normally restrict sign-ins coming from outside. Investigators noticed anomalous network flows: the Egnyte VM should have contacted Egnyte domains, but it connected to attacker-controlled domains proxied via Cloudflare. Snapshot analysis confirmed Brickstorm. They also found additional persistence attempts (including AGENTPSD) and later re-entry via an exposed firewall management interface, plus deployment of a second-stage Linux backdoor (PLENET) on Synology NAS. Fixes and reporting followed—including Egnyte Storage Sync v13.13 updates for a permissions issue. #CyberSecurity #IncidentResponse #ThreatHunting #M365Security #SupplyChainRisk #ZeroTrust
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论