


Perceptive Security
SOC/SIEM Consultancy

CISA warns of Chinese "BrickStorm" malware attacks on VMware servers
Published:
4 December 2025 at 18:19:55
Alert date:
5 December 2025 at 08:03:23
Source:
bleepingcomputer.com

CISA warns of Chinese hackers using BrickStorm malware to backdoor VMware vSphere servers. The campaign targets virtualization infrastructure with sophisticated malware designed to maintain persistent access. Chinese threat actors are actively exploiting VMware environments to establish footholds in targeted networks. The attacks pose significant risks to enterprise virtualization platforms and require immediate defensive measures.
Technical details
Mitigation steps:
Affected products:
VMware vSphere
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.