NSA/CSS - National Security Agency - Central Security Service

12/04/2025 | Press release | Distributed by Public on 12/04/2025 09:41

NSA Joins CISA to Release Guidance on Detecting BRICKSTORM Backdoor Activity

FORT MEADE, Md. -
FORT MEADE, Md. - The National Security Agency (NSA) is joining the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre for Cyber Security to detail the broad campaign of China state-sponsored cyber actors using the BRICKSTORM malware for long-term persistence on victim systems.

BRICKSTORM malware is a sophisticated backdoor that provides capabilities for secure command and control, remote system control, and long-term persistence.

Organizations-especially those within critical infrastructure, government services and facilities, and the Information Technology sector-are encouraged to use the indicators of compromise (IOCs) and detection signatures outlined in the report to detect BRICKSTORM backdoor activity. If BRICKSTORM, similar malware, or potentially related activity is detected, promptly report the compromise.

Read the full report here.

Visit our full library for more cybersecurity information and technical guidance.

NSA Media Relations [email protected] 443-634-0721

NSA/CSS - National Security Agency - Central Security Service published this content on December 04, 2025, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on December 04, 2025 at 15:41 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]