UNC5221 Brickstorm, Plenet, and AgentPSD access-maintenance malware activity
Malware Activity
Summary
Hide ▲
Show ▼
The Brickstorm malware set enabled UNC5221 / VerdantBamboo to keep long-term access inside victim infrastructure, including Microsoft 365, raising the risk of stealthy follow-on intrusion. The operation blended stolen credentials with SSL VPN access and proxying to avoid controls that would normally block entry. The malware also extended into internal appliances and supporting infrastructure, including a Synology NAS device and an affected managed services provider (MSP). Persistent access lasting at least 18 months made the compromise harder to detect and easier to re-use.
Related Happenings
Velvet Ant Linux login-layer persistence campaign
Campaign
H score41
First: 12.06.2026 21:17
Last: 12.06.2026 21:17
Sources 1
About this happening:
A Velvet Ant campaign was uncovered that quietly maintained access by backdooring Linux PAM and OpenSSH components, putting credential capture and command logging inside t...
Velvet Ant Linux login-layer persistence campaign
CampaignAbout this happening: A Velvet Ant campaign was uncovered that quietly maintained access by backdooring Linux PAM and OpenSSH components, putting credential capture and command logging inside t...
BRICKSTORM, PLENET, and AGENTPSD Linux appliance deployment
Malware Activity
H score40
First: 08.06.2026 13:27
Last: 08.06.2026 13:27
Sources 1
About this happening:
The deployment of BRICKSTORM, PLENET (aka GRIMBOLT), and AGENTPSD on Linux appliances expanded operator access with backdoor, proxying, remote command ex...
BRICKSTORM, PLENET, and AGENTPSD Linux appliance deployment
Malware ActivityAbout this happening: The deployment of BRICKSTORM, PLENET (aka GRIMBOLT), and AGENTPSD on Linux appliances expanded operator access with backdoor, proxying, remote command ex...
Tycoon2FA device-code phishing campaign targeting Microsoft 365
Campaign
H score46
First: 17.05.2026 17:43
Last: 17.05.2026 17:43
Sources 1
About this happening:
The Tycoon2FA phishing operation added device-code phishing to hijack Microsoft 365 accounts, expanding its ability to steal access tokens and reach email, calendar, a...
Tycoon2FA device-code phishing campaign targeting Microsoft 365
CampaignAbout this happening: The Tycoon2FA phishing operation added device-code phishing to hijack Microsoft 365 accounts, expanding its ability to steal access tokens and reach email, calendar, a...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
Campaign
H score37
First: 06.05.2026 16:02
Last: 06.05.2026 16:02
Sources 1
About this happening:
The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
CampaignAbout this happening: The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...
Dragon Boss Solutions LLC adware malicious update
Malware Activity
H score26
First: 16.04.2026 22:07
Last: 16.04.2026 22:07
Sources 1
About this happening:
A March 22, 2025 malicious update turned Dragon Boss Solutions LLC adware into an AV-disabling payload, exposing nearly 24,000 systems to follow-on abuse. The upda...
Dragon Boss Solutions LLC adware malicious update
Malware ActivityAbout this happening: A March 22, 2025 malicious update turned Dragon Boss Solutions LLC adware into an AV-disabling payload, exposing nearly 24,000 systems to follow-on abuse. The upda...
Timeline
-
05.06.2026 03:00 2 articles · 1mo ago
Volexity uncovers UNC5221 access to Microsoft 365 and internal systems
Initial DisclosureVolexity investigators uncover UNC5221, also tracked as VerdantBamboo, maintaining access to Microsoft 365 and other victim systems with Brickstorm, Plenet, and AgentPSD. The investigation finds the actor had been inside the victim network for at least 18 months before detection and had also compromised the victim organization's managed services provider (MSP), with access paths including an Egnyte Storage Sync system and the victim's web SSL VPN.
Show sources
- Chinese APT deploys new malware to keep access to hacked networks — www.bleepingcomputer.com — 05.06.2026 21:09
- Chinese APT deploys new malware to keep access to hacked networks — www.bleepingcomputer.com — 05.06.2026 21:09