Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

UNC5221 BRICKSTORM espionage against U.S. legal and SaaS firms

Updated 05.12.2025 10:14
Case score 57
Case score 57 Members 1 Latest activity 05.12.2025 10:14
Members 1 First seen 24.09.2025 17:33 Last seen 24.09.2025 17:33 Updated 05.12.2025 10:14

Overview

UNC5221's **BRICKSTORM** espionage campaign targets U.S. legal services, SaaS providers, BPOs, and technology companies by planting a stealth backdoor on edge appliances and then moving into virtualization and identity layers. The activity has been observed since March 2025, with an average dwell time of 393 days, theft of source code and other intellectual property, and prior exploitation of **Ivanti Connect Secure** flaws **CVE-2023-46805** and **CVE-2024-21887**. Google released a **BRICKSTORM** shell script scanner, but the full victim count and the complete downstream impact remain unknown.