Site navigation

Google Warns of China-linked Cyber-attacks Targeting Tech

Tom Quinn

,

BRICKSTORM malware
Google’s Mandiant threat intelligence has warned that BRICKSTORM malware poses major risks to tech and legal firms, with delayed activation and anti-forensics measures leaving organisations blind to intrusion.

Hackers linked to the Chinese government are targeting tech companies, software providers and legal firms in a backdoor attack using malware to extract valuable intellectual property and data, and leave access for further downstream attacks.

In a new blog post detailing the threat, Google’s incident response arm, Mandiant, said that it has been tracking the intrusions related to the threat actor dubbed UNC5221 since March this year, with the attackers aiming to gain a long-term foothold by using BRICKSTORM malware.

This allows hackers to target edge appliances that lack traditional security tools, enabling lateral movement, credential theft, and data exfiltration, and with an average dwell time of 393 days, security teams are often left blind to the initial intrusion in their logs.

In one notable instance, researchers found one malware sample with a ‘delay’ timer built in that waited for a hard-coded date months in the future before becoming active.

According to Google’s report, the threat actors focus on systems that lack built-in tools for detecting and monitoring threats on devices, like laptops or phones. These typically include infrastructure such as email gateways and vulnerability scanners, which don’t support standard endpoint detection and response (EDR). 

Although investigators have spotted BRICKSTORM on other systems early on in its lifecycle, Google said it remains unclear how they gained access in most cases. Once inside, the hackers used post-exploitation scripts to cover their tracks, along with anti-forensics functions to hide how they got in.


Recommended reading


Further signs that these nefarious cyber operations are tied to state-backed adversaries are that the hackers, across multiple intrusions, were intent on exploiting the emails of key individuals within organisations, targeting the mailboxes of core developers, system administrators, and individuals working in areas tied to China’s economic interests and intelligence operations.

Google said the BRICKSTORM campaign was likely driven by goals including geopolitical espionage, system access, and IP theft that would support further exploit development; however, the value in targeting the US legal space was thought primarily to be gathering information related to US national security and international trade. 

To aid organisations in hunting for BRICKSTORM activity in their environments, Mandiant released a scanner script, with Charles Carmakal, chief technology officer at Mandiant Consulting, telling reporters: “We have no doubt that organisations will use our tools to hunt for this adversary, and they will find evidence of compromise in their environments.

“And it may be active compromises, it might be historic compromises, but many of our organisations are going to discover that they were dealing with this adversary.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data