Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
A maximum-severity vulnerability in Dell RecoverPoint for Virtual Machines allowed a suspected China-linked APT cluster to operate undetected in North American organizations for roughly 18 months. The flaw, identified as CVE-2026-22769 with a CVSS 10.0 score, was added to CISA's Known Exploited Vulnerabilities catalog on February 18, 2026: for U.S. federal agencies the mandatory patch deadline is February 21, 2026. For everyone else, the risk is twofold: an active compromise currently underway, or a historical intrusion never detected.
- CVE-2026-22769 carries a CVSS 10.0 score and is caused by a hard-coded credential for the "admin" user in the Dell RecoverPoint for VMs Apache Tomcat Manager instance.
- The UNC6201 cluster, assessed by Mandiant as a suspected China-nexus actor distinct from UNC5221, exploited the flaw as a zero-day from mid-2024.
- The attack chain culminates in the deployment of BRICKSTORM and its evolution GRIMBOLT, a C# backdoor compiled with native ahead-of-time (AOT) compilation to evade analysis.
- UNC6201 employed temporary virtual network interfaces ("Ghost NICs") for lateral pivoting, then deleted them to cover tracks.
The Entry Point: A Hard-Coded Credential in Tomcat Manager
The vulnerability resides in the Apache Tomcat Manager instance embedded in Dell RecoverPoint for Virtual Machines. According to the vendor bulletin, cited by Mandiant/Google Threat Intelligence Group, an unauthenticated remote attacker who knows the hard-coded credential can gain unauthorized access to the underlying operating system and establish root-level persistence. The affected credential belongs to the "admin" user for the Tomcat Manager instance.
Affected versions are those prior to 6.0.3.1 HF1; RecoverPoint Classic is not vulnerable. The exploitation mechanism is linear but devastating: authenticate to Tomcat Manager, upload the SLAYSTYLE web shell via the /manager/text/deploy endpoint, execute commands with root privileges, then deploy the BRICKSTORM or GRIMBOLT backdoors.
BRICKSTORM and GRIMBOLT: Evolution of a Backdoor for "Blind" Appliances
BRICKSTORM has been known since 2024 in campaigns linked to UNC5221; in the UNC6201 case, Mandiant observed an evolution dubbed GRIMBOLT starting in September 2025. Charles Carmakal of Mandiant describes GRIMBOLT as "a C# backdoor compiled using native ahead-of-time (AOT) compilation, which makes it harder to reverse engineer." Google/Mandiant adds that "GRIMBOLT is even more capable of blending in among the system's native files."
The choice of AOT is significant: it eliminates the managed IL code typical of .NET, reducing the surface analyzable by standard tools and complicating signature-based behavioral detection. This characteristic combines with a particularly insidious deployment vector: disaster recovery appliances, by their nature, typically do not support EDR solutions. Charles Carmakal highlights that "nation-state threat actors continue to target systems that do not commonly support EDR solutions, which makes it very difficult for victim organizations to know they are compromised and significantly prolongs intrusion dwell time."
"The actor is likely still active in unpatched and unremediated environments, and since exploitation has been occurring since mid-2024, they have had significant time to establish persistence and conduct long-term espionage" — Rich Reece, Manager Mandiant Consulting at Google Cloud
Ghost NICs: Invisible Pivoting and Track Erasure
A distinctive UNC6201 tactic, documented by Google/Mandiant, is the use of "Ghost NICs": temporary virtual network interfaces created to pivot within internal environments or SaaS infrastructure, subsequently deleted to cover tracks. This technique turns the disaster recovery appliance — a system designed for resilience, not active security — into a mobile, hidden bridge to adjacent assets.
The indication of SaaS provider targeting, combined with GRIMBOLT's ability to blend in with system files, raises the risk of downstream compromise for customers of services hosted in the initially breached organizations. The dossier does not specify identified supply-chain victims.
CISA KEV and the Three-Day Reaction Mandate
CISA added CVE-2026-22769 to the Known Exploited Vulnerabilities catalog on February 18, 2026, associating it with the Binding Operational Directive for Federal Civilian Executive Branch agencies. The remediation deadline is February 21, 2026: a three-day window reflecting the perceived severity and confirmation of active exploitation in government environments.
Team Cymru published an analysis of GRIMBOLT's C2 infrastructure on March 5, 2026, identifying an X.509 certificate with common name WIN-DO6FVJH67FN and IP addresses 149.248.11[.]71, 140.82.18[.]134, 66.42.111[.]219 on Vultr VPS. These indicators, while not a substitute for full remediation, provide threat-hunting elements for networks that hosted RecoverPoint during the relevant time windows.
Immediate Actions
For organizations running Dell RecoverPoint for Virtual Machines, four actions are priorities based on the documented data.
Verify the version and apply 6.0.3.1 HF1. This is the only release that fixes CVE-2026-22769; prior versions are vulnerable. RecoverPoint Classic requires no action.
Investigate for historical presence of SLAYSTYLE, BRICKSTORM, or GRIMBOLT. Rich Reece of Mandiant emphasizes that "the actor is likely still active in unpatched and unremediated environments." The exploitation window from mid-2024 implies a compromise may not have triggered alarms: backup appliances typically lack EDR, and GRIMBOLT is designed to evade detection.
Search for Ghost NIC indicators in network logs. The creation and deletion of temporary virtual interfaces, if logged, can signal lateral pivoting even in the absence of detected on-disk malware. The dossier does not specify automated detection tooling for this tactic.
Assess exposure of SaaS environments and downstream infrastructure. The targeting pattern documented by Mandiant includes service providers; a RecoverPoint compromise can serve as an entry point to tenant and customer data. The dossier does not quantify this risk or list confirmed downstream victims.
Disaster Recovery as a Privileged Attack Surface
The UNC6201 campaign is not an isolated incident but a structural pattern: nation-state threat actors are shifting focus and resources toward systems that, by architecture, do not support standard detection tools. Disaster recovery appliances have privileged access to data, communicate with multiple network segments, and are managed with less aggressive patching cycles than user endpoints. The result is "geological" dwell time, measured in hundreds of days rather than weeks.
The BRICKSTORM-to-GRIMBOLT transition, dated September 2025, raises unanswered questions: whether it was a scheduled update or a response to partial disclosure. What is documented is the direction of technical investment: AOT compilation, Ghost NICs, and SaaS provider targeting indicate an operation with resources and planning, not tactical opportunism.
For defenders, the lesson is spatial before technical: blind spots form where security was not designed to exist. And where there is no EDR, the actor has all the time needed to make the system indistinguishable from its own code.
Information verified against cited sources and current as of publication.
Sources
- https://thehackernews.com/2026/02/dell-recoverpoint-for-vms-zero-day-cve.html
- https://www.cisa.gov/news-events/alerts/2026/02/18/cisa-adds-two-known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://thehackernews.com/2024/05/hackers-created-rogue-vms-to-evade.html
- https://thehackernews.com/2025/09/unc5221-uses-brickstorm-backdoor-to.html
- https://thehackernews.com/2024/01/nation-state-actors-weaponize-ivanti.html
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.