EPISODE · Sep 26, 2025 · 5 MIN
China's Cyber Espionage Spree: BRICKSTORM, ArcaneDoor, and the Art of Persistence
from Cyber Sentinel: Beijing Watch · host Inception Point AI
This is your Cyber Sentinel: Beijing Watch podcast. Welcome back, listeners—Ting here with your front-row seat to the sharpest cyber skirmishes on Cyber Sentinel: Beijing Watch. Hope you’ve got your two-factor authentication set, because these past days in Chinese cyber antics have been less “script kiddie” and more “Hollywood thriller with a side of Linux persistence.” No fluff, straight in. The biggest headline needs only one name: BRICKSTORM. This is the Go-based backdoor that’s been making seasoned sysadmins shiver since March, and according to Google’s Threat Intelligence crew, it’s the calling card of APT UNC5221—a China-nexus operator that’s got more persistence than your college roommate’s phishing scams. They’ve spent over a year slithering through U.S. tech, legal, and SaaS sector networks, pivoting from Linux appliances straight to the heart of VMware vCenter and ESXi hosts. We’re talking almost invisible lateral movement, stolen admin credentials, and regular use of zero-days to stay out of sight while siphoning data—think full blast espionage. Mandiant’s got receipts tying UNC5221 to a style of attack where persistence is king: they alter startup scripts, drop web shells like SLAYSTYLE, and even leverage Microsoft Entra ID Enterprise App permissions to quietly vacuum up email from key targets—mostly developers, IT admins, and execs linked to Chinese economic interests. Now, that’s just the custom malware saga. Over at Cisco, there’s a sequel nobody wanted—ArcaneDoor. Cisco had to rush out emergency patches for two zero-day vulnerabilities in its firewall platforms after Chinese-linked actors, possibly tied to the same threat clusters, exploited them to plant malware and even manipulate device memory for deep stealth. According to Cisco’s own incident reports, the attackers could crash firewalls to erase their footprints and tamper with critical system files. Federal agencies—shout out CISA—have hit the panic button, issuing a one-day deadline for every agency to find vulnerable firewalls, dump memory for forensic analysis, and yank any out-of-support devices offline. The victim list reads like a tech industry who’s-who: everything from U.S. government networks and critical infrastructure to the legal giants handling trade disputes. And don’t think this ends in the U.S.; the UK’s National Cyber Security Centre is on maximum alert, publishing malware analysis and demanding global vigilance. Attribution-wise, Mandiant and Google are confident the fingerprints trace straight to PRC state-backed APTs. CISA’s a bit more diplomatic but even they aren’t mincing words about the urgency or scale. International response? The U.S. and allies are trading TTPs, rushing patches, and running joint cyber drills. India and the U.S. have called for direct confrontation of the shared Chinese cyber threat—even police in the UK are now making arrests linked to ripple-effect ransomware schemes. Strategic implication: China’s cyber doctrine is clearl This content was created in partnership and with the help of Artificial Intelligence AI.
Embed this episode
NOW PLAYING
China's Cyber Espionage Spree: BRICKSTORM, ArcaneDoor, and the Art of Persistence
No transcript for this episode yet
Similar Episodes
No similar episodes found.