VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

Jun 8, 2026

A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems.

The activity has been attributed by Volexity to a threat cluster it tracks as VerdantBamboo, which it said overlaps with hacking groups known as Clay Typhoon (Microsoft),

Get Free Report & Network Analysis

Please check your email for the free report.