CyberzSOC

Publication detail
← Back to advisories & guidance

BRICKSTORM Backdoor ↗ source

December 4, 2025 NSA Analysis Report
Co-sealed by: CCCS, CISA, NSA

Summary

and Cyber Centre are releasing this Malware Analysis Report to share indicators of compromise (IOCs) and detection signatures based off analysis of 12 BRICKSTORM samples. CISA, NSA, and Cyber Centre urge organizations to use the IOCs and detection signatures to identify BRICKSTORM malware samples. CISA, NSA, and Cyber Centre updated this Malware Analysis Report on Feb. 11, Last Update Description 2026, with analysis, IOCs, and detection signatures from a new variant of BRICKSTORM. ▪ Use the IOCs and detection signatures to identify BRICKSTORM samples. ▪ If BRICKSTORM, similar malware, or potentially related activity is detected,

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.