Skip to main content
Mallory
Back to intelligence
state-sponsored-espionagethird-party-vendor-breachpersistence-methodperimeter-device-exposure

VerdantBamboo Used BRICKSTORM and PLENET to Persist via Edge Appliances

Updated 13h agoFirst seen Jun 4, 20266 sources

Volexity reported that the China-linked threat actor VerdantBamboo—also tracked as WARP PANDA and UNC5221—compromised an organization through its managed services provider and maintained access for at least 18 months by abusing edge infrastructure and proprietary appliances. Investigators found the actor on an Egnyte Storage Sync appliance, where it deployed BRICKSTORM as its primary implant and used AGENTPSD as a fallback reverse shell, then pivoted with stolen credentials and SSL VPN access to reach internal systems and Microsoft 365 while bypassing Conditional Access protections.

The intrusion also affected the victim’s MSP, where Volexity found a pfSense firewall running a FreeBSD variant of BRICKSTORM and assessed with medium confidence that the MSP breach was the likely initial access path. During the investigation, Volexity identified a local privilege escalation issue tied to sudo permissions for Egnyte’s default egnyteservice account, later fixed in Storage Sync v13.13, and documented a new .NET Native AOT backdoor named PLENET on a Synology NAS. The findings indicate VerdantBamboo deliberately targets appliances and firewall-adjacent systems that often lack EDR coverage, using them as covert proxies and long-term persistence points.

Share:
VerdantBamboo Used BRICKSTORM and PLENET to Persist via Edge Appliances
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 8, 202616h ago

Egnyte releases Storage Sync v13.13 with privilege escalation fix

Egnyte released Storage Sync version 13.13 in March 2026, fixing the local privilege escalation flaw affecting the default egnyteservice account on compromised appliances. The vulnerability had been abused in the intrusion investigated by Volexity.

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

Gurucul reports UNC5221 campaign targeting U.S. law firms

On June 8, 2026, Gurucul published research on an ongoing China-linked espionage campaign attributed to UNC5221 targeting U.S. law firms and technology organizations. The report said the attackers exploited zero-days, deployed BRICKSTORM, maintained access for more than a year, and stole sensitive legal, trade, and national security information.

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms | Community Portal | Gurucul
Jun 4, 20265d ago

Volexity publishes VerdantBamboo intrusion findings

On June 4, 2026, Volexity published its investigation linking the intrusion to VerdantBamboo, also tracked as WARP PANDA and UNC5221. The report documented the actor's focus on proprietary appliances and edge devices, including a pfSense firewall at the compromised MSP running a FreeBSD variant of BRICKSTORM.

VerdantBamboo: Just Another BRICKSTORM in the Firewall | Volexity

Egnyte fixes local privilege escalation in Storage Sync v13.13

Volexity identified a local privilege escalation condition in Egnyte Storage Sync involving sudo permissions for the default egnyteservice account. Egnyte later fixed the issue in Storage Sync version 13.13.

VerdantBamboo: Just Another BRICKSTORM in the Firewall | Volexity

Attackers maintain long-term access using BRICKSTORM and other implants

Following the intrusion, VerdantBamboo maintained access for at least 18 months by deploying BRICKSTORM on edge and appliance systems, AGENTPSD as a fallback reverse shell, and the PLENET backdoor on a Synology NAS. The actor also used compromised credentials and SSL VPN access to pivot internally and access Microsoft 365 while evading Conditional Access controls.

VerdantBamboo: Just Another BRICKSTORM in the Firewall | Volexity
Sep 1, 20259mo ago

VerdantBamboo compromises victim environment via likely MSP access

In September 2025, Volexity investigated an intrusion involving an Egnyte Storage Sync appliance and determined that VerdantBamboo had compromised the victim environment. Volexity assessed with medium confidence that a compromise of the victim's managed services provider was the likely initial access path.

VerdantBamboo: Just Another BRICKSTORM in the Firewall | Volexity
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

33 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.