Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNC5221 Brickstorm, Plenet, and AgentPSD access-maintenance malware activity

Malware Activity
First reported
Last updated
Happening score
H score 16
1 unique sources, 1 articles

Summary

Hide ▲

The Brickstorm malware set enabled UNC5221 / VerdantBamboo to keep long-term access inside victim infrastructure, including Microsoft 365, raising the risk of stealthy follow-on intrusion. The operation blended stolen credentials with SSL VPN access and proxying to avoid controls that would normally block entry. The malware also extended into internal appliances and supporting infrastructure, including a Synology NAS device and an affected managed services provider (MSP). Persistent access lasting at least 18 months made the compromise harder to detect and easier to re-use.

Related Happenings

Velvet Ant Linux login-layer persistence campaign

Campaign
H score41 First: 12.06.2026 21:17 Last: 12.06.2026 21:17 Sources 1

About this happening: A Velvet Ant campaign was uncovered that quietly maintained access by backdooring Linux PAM and OpenSSH components, putting credential capture and command logging inside t...

BRICKSTORM, PLENET, and AGENTPSD Linux appliance deployment

Malware Activity
H score40 First: 08.06.2026 13:27 Last: 08.06.2026 13:27 Sources 1

About this happening: The deployment of BRICKSTORM, PLENET (aka GRIMBOLT), and AGENTPSD on Linux appliances expanded operator access with backdoor, proxying, remote command ex...

Tycoon2FA device-code phishing campaign targeting Microsoft 365

Campaign
H score46 First: 17.05.2026 17:43 Last: 17.05.2026 17:43 Sources 1

About this happening: The Tycoon2FA phishing operation added device-code phishing to hijack Microsoft 365 accounts, expanding its ability to steal access tokens and reach email, calendar, a...

MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy

Campaign
H score37 First: 06.05.2026 16:02 Last: 06.05.2026 16:02 Sources 1

About this happening: The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...

Dragon Boss Solutions LLC adware malicious update

Malware Activity
H score26 First: 16.04.2026 22:07 Last: 16.04.2026 22:07 Sources 1

About this happening: A March 22, 2025 malicious update turned Dragon Boss Solutions LLC adware into an AV-disabling payload, exposing nearly 24,000 systems to follow-on abuse. The upda...

Timeline

  1. 05.06.2026 03:00 2 articles · 1mo ago

    Volexity uncovers UNC5221 access to Microsoft 365 and internal systems

    Initial Disclosure

    Volexity investigators uncover UNC5221, also tracked as VerdantBamboo, maintaining access to Microsoft 365 and other victim systems with Brickstorm, Plenet, and AgentPSD. The investigation finds the actor had been inside the victim network for at least 18 months before detection and had also compromised the victim organization's managed services provider (MSP), with access paths including an Egnyte Storage Sync system and the victim's web SSL VPN.

    Show sources