Netskope Threat Labs

BRICKSTORM

ATP Sandbox Adv. HeuristicsAVNetskope IPS

BRICKSTORM is a detection name for destructive malware that damages systems, including variants that target virtualization infrastructure and erase data on compromised hosts. Malware of this class can render servers and virtual machines unbootable, which forces organizations into lengthy recovery from backups. Because its impact is disruption rather than encryption for ransom, defenders treat BrickStorm detections as evidence of a serious intrusion in progress.

First seen
September 2025
Last seen
October 2026

25 techniques across 9 tactics.

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process

TA0005 Stealth

TA0007 Discovery

  • T1057Process Discovery
  • T1083File and Directory Discovery

TA0009 Collection

  • T1005Data from Local System

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0040 Impact

TA0112 Defense Impairment

  • T1690Prevent Command History Logging
Alert Name
ByteCode-JAVA.Trojan.BrickStorm
Generic.BrickStorm.A.63CC9791
Linux.Backdoor.BrickStorm
Linux.Trojan.BrickStorm
Trojan.Generic.BrickStorm.39193986
Trojan.Linux.BrickStorm.58759
Trojan.Linux.BrickStorm.58768
Trojan.Linux.BrickStorm.58769
Trojan.Linux.BrickStorm.58770
Trojan.Linux.BrickStorm.B