Description
BRICKSTORM is a detection name for destructive malware that damages systems, including variants that target virtualization infrastructure and erase data on compromised hosts. Malware of this class can render servers and virtual machines unbootable, which forces organizations into lengthy recovery from backups. Because its impact is disruption rather than encryption for ransom, defenders treat BrickStorm detections as evidence of a serious intrusion in progress.
Stats
- First seen
- September 2025
- Last seen
- October 2026
MITRE ATT&CK techniques
25 techniques across 9 tactics.
TA0003 Persistence
- T1543Create or Modify System Process
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1027.013Encrypted/Encoded File
- T1036Masquerading
- T1036.005Match Legitimate Resource Name or Location
- T1070Indicator Removal
- T1140Deobfuscate/Decode Files or Information
- T1574Hijack Execution Flow
- T1574.007Path Interception by PATH Environment Variable
- T1678Delay Execution
TA0009 Collection
- T1005Data from Local System
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
TA0040 Impact
- T1489Service Stop
TA0112 Defense Impairment
- T1690Prevent Command History Logging
Alert name variants
| Alert Name |
|---|
| ByteCode-JAVA.Trojan.BrickStorm |
| Generic.BrickStorm.A.63CC9791 |
| Linux.Backdoor.BrickStorm |
| Linux.Trojan.BrickStorm |
| Trojan.Generic.BrickStorm.39193986 |
| Trojan.Linux.BrickStorm.58759 |
| Trojan.Linux.BrickStorm.58768 |
| Trojan.Linux.BrickStorm.58769 |
| Trojan.Linux.BrickStorm.58770 |
| Trojan.Linux.BrickStorm.B |