BRICKSTORM malware is being used by suspected China-nexus actor, UNC5221, in a stealthy espionage campaign.
-Avg dwell time: 393 days
-Targets: US legal, SaaS, BPOs & tech firms
We have released a scanner, IOCs, and guidance to help defenders.
Full analysis here: bit.ly/4pT3pku