ADVERTISEMENT

Law offices, tech firms targeted in new “BRICKSTORM” Chinese espionage campaign

BRICKSTORM, a new “highly evasive” malware campaign linked to Beijing, has been targeting the legal services and technology sectors for more than a year, according to new research published by Google’s Mandiant on Wednesday.

Blue eagle representing USA and a red dragon representing China on a rollercoaster

Image by Cybernews.

Stefanie Schappert
Stefanie Schappert Senior Journalist
September 24, 2025 Updated: September 25, 2025 4 min read
Key takeaways:
Brickstorm espionage malware campaign target sectors
Image by Google Mandiant.

Emails are of particular interest

Maintaining persistent access

ADVERTISEMENT
prompt injection attack
Image by Cybernews.
Chinese nation-state sponsored APT, cyber espionage
Image by vchal | Shutterstock

Indicators of compromise lead to scanner tool

Ernestas Naprys Gintaras Radauskas Paulina Okunyte vilius
Don't miss our latest stories on Google News
Add us as your Preferred Source on Google.
  • Identify a compromise 100% of the time.
  • Detect all variants of BRICKSTORM (it is specific to one YARA rule).
  • Tell you if a device is vulnerable to exploitation.
  • Scan for other IOCs like logs, processes, or persistence mechanisms.

ADVERTISEMENT