Skip to content
Briefings are running a touch slower this week while we rebuild the foundations.See roadmap
Cybersecurity: Threats and Defences
29MAY

BRICKSTORM dwell hits 393 days, Mandiant

3 min read
14:17UTC

Mandiant's M-Trends 2026 set the China-nexus benchmark at a 393-day average dwell inside VMware hypervisors. The telemetry built for malware does not see it.

TechnologyAssessed
Key takeaway

China-nexus attackers are averaging over a year of undetected access inside the virtualisation layer.

Mandiant, the Google-owned incident-response firm, published its annual M-Trends 2026 report this month based on more than 500,000 hours of incident response, disclosing a 393-day average undetected dwell time for UNC5221's BRICKSTORM campaign 1. UNC5221 is a China-nexus espionage cluster; BRICKSTORM is a Go-language backdoor that lives on VMware vCenter and ESXi hosts, the management plane and the hypervisor of most enterprise virtualisation estates. The primary targets are US and UK legal services, Business Process Outsourcers (BPOs, firms that run back-office operations on behalf of clients), Software-as-a-Service (SaaS) providers and technology companies.

The tradecraft bypasses classic endpoint telemetry entirely. A companion servlet filter called BRICKSTEAL captures the vCenter Hypertext Transfer Protocol (HTTP) Basic Authentication credentials used by administrators; domain-controller virtual machines are cloned at the hypervisor layer for offline credential extraction; and mailbox access is achieved through legitimate Microsoft Entra Identity (Entra ID) Enterprise Apps granted the `mail.read` or `full_access_as_app` permission scopes. Command-and-control traffic is relayed through Cloudflare Workers and Heroku, meaning blocklist-based network defences see benign cloud traffic rather than known-bad infrastructure.

The 393-day figure is a calibration point. Any enterprise whose detection-to-eviction time exceeds that number is performing below the observed China-nexus median attacker advantage. For London legal-sector incident-response leads in particular, the benchmark sits uncomfortably close to the reality of a firm that runs a six-month threat-hunt cycle and processes no hypervisor-level forensic data between cycles. EDR sensors, designed to catch malware running on laptops and servers, see nothing at the ESXi layer because they are not installed there.

Deep Analysis

In plain English

UNC5221 is a Chinese hacking group that broke into the infrastructure layer of organisations' computer systems: specifically, the software that runs virtual machines. Think of it as breaking into the machine room that controls all the offices in a building, rather than breaking into the offices themselves. The group spent an average of 393 days inside victims' systems before being detected. During that time, they copied credentials, cloned domain controller virtual machines for offline analysis, and accessed email accounts through permissions they had quietly granted themselves. Mandiant, the Google-owned threat intelligence firm, revealed this in their annual M-Trends 2026 report, which is based on over 500,000 hours of incident response work. The affected organisations were primarily US and UK law firms, business services companies, and technology providers.

Deep Analysis
Root Causes

VMware vCenter and ESXi are the hypervisor management plane for virtualised enterprise environments. Compromising them gives an attacker a god's-eye view of all virtual machines without touching any of them directly. Standard endpoint security agents run inside virtual machines; they cannot monitor the hypervisor layer that controls them.

The use of Cloudflare Workers and Heroku as command-and-control relays exploits a structural limitation of network monitoring: both platforms serve legitimate traffic for millions of organisations, making their domain names and IP ranges uncategorisable as malicious by conventional threat-intelligence feeds. Blocking them would break legitimate business applications.

What could happen next?
  • Risk

    Any enterprise whose detection and response time is shorter than 393 days but whose vCenter and ESXi logging retention is less than 393 days cannot determine retrospectively whether it was compromised by this campaign.

  • Consequence

    UK law firms and business process outsourcers handling confidential client data face regulatory obligations under both GDPR and professional privilege rules if BRICKSTORM intrusions are retrospectively discovered during incident reviews triggered by this advisory.

First Reported In

Update #1 · Stryker MDM wipe exposes identity perimeter

Google Cloud / Mandiant· 17 Apr 2026
Read original
Causes and effects
This Event
BRICKSTORM dwell hits 393 days, Mandiant
The China-nexus attacker median advantage is now more than a year of undetected access inside legal firms, BPOs and SaaS providers.
Different Perspectives
Google Threat Intelligence Group
Google Threat Intelligence Group
GTIG's attribution of the GitHub breach extends UNC6780's documented arc from SAP npm through Cisco AI Defense to GitHub's own estate; its 36-hour LiteLLM exploitation set the speed benchmark CISA AA26-148A is designed to address. GTIG's published tracking gives defenders the actor profile needed to assess their own developer-toolchain exposure.
Enterprise security buyers / CISO community
Enterprise security buyers / CISO community
For enterprise security leaders, two KEV AI-orchestration entries in three weeks (LiteLLM 8 May, Langflow 21 May) convert shadow AI tooling from a governance risk to a confirmed attack surface requiring immediate software asset inventory. The 65 per cent gap in enterprise AI tool inventories documented by Wiz Research is now a liability rather than a compliance footnote.
DSIT / UK Government
DSIT / UK Government
DSIT framed the £14.7 billion sector figure and the Cyber Resilience Pledge as a paired signal: commercial strength alongside supply-chain accountability, with £90 million targeting the NHS supplier exposure this briefing's threat events directly illustrate. The voluntary Pledge's enforceability gap, prior to the Cyber Security and Resilience Bill reaching Royal Assent, is the question its launch does not answer.
GitHub / Microsoft
GitHub / Microsoft
GitHub confirmed that no customer repositories or user data were affected by the Nx Console breach, but acknowledged approximately 3,800 internal repositories were cloned and referred to CISA Alert AA26-148A's allow-listing guidance. The incident puts Microsoft in the position of operating a marketplace whose publisher-verification gap is now a documented attack vector in a federal advisory.
Tsinghua University Institute for International Strategic Studies
Tsinghua University Institute for International Strategic Studies
Beijing-aligned commentary rejects US attribution of PRC-nexus clusters (UNC2814, APT45, UAT-8616) as politically motivated framing, characterising the April sixteen-agency joint advisory as coordinated Western pressure rather than independent technical assessment.
Cisco
Cisco
Cisco has not confirmed the UNC6780 breach scope beyond the named AI Defense and AI Assistant projects; GitHub confirmed an investigation. CVE-2026-20182 is the sixth Cisco SD-WAN KEV entry in 2026, reaching that milestone the same week UNC6780's source-code visibility into the portfolio became public.