The United States and Canada publicly disclosed a joint advisory on December 5, 2025, detailing the BRICKSTORM malware, attributed to Chinese state-sponsored actors. CISA analyzed eight samples collected from victim organizations, documenting an advanced persistence architecture and access maintained for over a year and a half in at least one documented case. The operation marks an escalation in Chinese threat strategy against North American critical infrastructure.
- CISA, NSA, and the Canadian Centre for Cyber Security signed a joint advisory on BRICKSTORM, malware deployed by Chinese state-sponsored actors against government and IT sector organizations.
- CISA analyzed eight BRICKSTORM samples obtained from victim organizations, including one organization with CISA incident response.
- In one documented case, attackers maintained persistent access from April 2024 to September 3, 2025: over 17 months of persistence.
- The malware was deployed against VMware vSphere, Broadcom's virtual machine management product, indicating a hypervisor-level compromise strategy.
From Volt Typhoon to BRICKSTORM: The New Phase of Pre-Positioning
The joint advisory places BRICKSTORM in an evolutionary line already traced by Volt Typhoon, the Chinese pre-positioning operation in US critical infrastructure revealed in 2023. The qualitative difference lies in documented operational capability: while Volt Typhoon aimed for silent infiltration and preparation of future access, BRICKSTORM integrates self-healing mechanisms that make its persistence actively resistant to removal.
The statement by Madhu Gottumukkala, CISA acting director, sets the strategic frame with precision. The malware does not serve espionage alone; its purpose is "embedding themselves to enable long-term access, disruption, and potential sabotage." The word "potential" is deliberate: sabotage not yet executed, but capability built to be activated. This pattern, known in military doctrine as preparation of the environment, turns every compromise into a latent threat of operational disruption.
Technical Architecture: Persistence That Self-Heals
CISA's analysis of eight samples reveals a sophisticated remote control architecture. BRICKSTORM hides communications with command-and-control servers, executes lateral movement within victim networks, tunnels traffic to bypass segmentation controls, and possesses mechanisms to automatically reinstall or restart if interrupted. This self-repair capability distinguishes the malware from conventional backdoors: persistence does not depend on a single foothold, but on a distributed survival logic.
Targeting VMware vSphere amplifies the problem. Compromising the hypervisor yields visibility and control over the entire virtualized stack, with potential access to multiple virtual machines regardless of their logical segmentation. The dossier does not specify whether vSphere access was obtained via exploit of a known vulnerability, weak configuration, or another vector; this gap makes it impossible, at present, to define a precise exposure perimeter.
"embedding themselves to enable long-term access, disruption, and potential sabotage"
— Madhu Gottumukkala, acting director CISA
A 17-Month Timeline and the Boundaries of Official Silence
The case with the greatest temporal detail shows attackers penetrating an organization in April 2024 and maintaining continuous access until September 3, 2025. Over 17 months of undetected presence, or detected but not ejected. This duration raises questions about the efficacy of detection controls in virtualized environments, where visibility into the hypervisor layer is typically more limited than on physical endpoints.
CISA, through Nick Andersen, Executive Assistant Director, declined to disclose the total number of targeted government organizations and details of post-penetration actions. This operational silence is consistent with standard practice for ongoing investigations, but leaves critical questions unanswered: how many infrastructures are currently compromised, which sectors beyond government and IT are involved, and whether BRICKSTORM represents a single operation or a platform distributed to multiple actors.
Why It Matters
The dossier published by CISA presents significant gaps for those who must translate the alert into concrete action. The source does not specify the initial access vector for BRICKSTORM: exploit of VMware vSphere, compromised credentials, or another vector remains undeclared. No infrastructure overlaps emerge linking the actor to a previously identified Chinese APT group.
CISA has not quantified the total number of victims, nor detailed the actions executed by attackers during the 17 months of access. The exact geographic scope of victims beyond "US and Canada" is not specified. The advisory does not associate BRICKSTORM with specific CVE vulnerabilities, making it impossible to prioritize patches on an identificatory basis.
What remains documented is sufficient to elevate risk: the combination of self-healing persistence, hypervisor targeting, and declared potential sabotage capability shifts the Chinese threat from intelligence collection to preparation of operational effects. Organizations with VMware vSphere infrastructure in government and IT sectors have published indicators of compromise, but effective detection requires visibility into the vSphere hypervisor layer that many security architectures do not systematically cover.
Open Questions on the Collective Response
The joint CISA-NSA-Canadian Centre advisory, for all its gravity, does not clarify whether the three agencies possess intelligence on activation commands or actor operational timelines. Gottumukkala's statement speaks of "potential sabotage," not imminent sabotage: this linguistic calibration, if it reflects intelligence assessment, suggests the pre-positioning window remains open. If it reflects only communicative caution, the gap between public alert and classified information remains unmeasurable.
The publication of YARA and SIGMA rules by CISA offers a detection channel, but their efficacy depends on the ability to acquire memory and logs from the vSphere hypervisor layer, operationally complex in many organizations. The dossier does not document whether these rules have already been validated in production environments or whether their deployment has yielded additional detections.
The BRICKSTORM case, finally, restates a structural tension in cyber deterrence: public attribution to "Chinese state" without identification of a specific group, documentation of advanced offensive capabilities, and simultaneous reticence on operational details create an ambiguous signal. Targeted actors receive a technical alert; the attributor receives confirmation of exposure without immediate costs. Whether this schema constitutes sufficient deterrence, or instead normalizes pre-positioning as acceptable below the threshold of response, is a question the advisory does not resolve.
Information is based on the cited source and current as of publication.
Sources
- https://it.slashdot.org/story/25/12/05/2135231/chinese-linked-hackers-use-backdoor-for-potential-sabotage-us-and-canada-say
- https://www.cisa.gov/news-events/news/cisa-nsa-and-cyber-centre-warn-critical-infrastructure-brickstorm-malware-used-peoples-republic
- https://slashdot.org/
- https://slashdot.org/recent
- https://slashdot.org/popular
- https://slashdot.org/polls