
VerdantBamboo's BSD BRICKSTORM Signals China-Nexus Pivot to Appliance Supply Chains Beyond Windows Targets
China-linked VerdantBamboo expands BRICKSTORM to BSD/Linux appliances via MSPs, exposing overlooked supply-chain risks in proprietary devices that evade EDR.
The deployment of a native BSD variant of BRICKSTORM on pfSense firewalls and Synology NAS devices marks a deliberate expansion by VerdantBamboo (overlapping Clay Typhoon/UNC5221) into environments lacking standard EDR coverage. Volexity's September 2025 incident response revealed initial compromise via Egnyte Storage Sync, followed by lateral movement through an MSP's pfSense appliance using stolen admin credentials and web SSL VPN abuse. This mirrors patterns seen in UNC6201's exploitation of Dell RecoverPoint (CVE-2026-22769) since mid-2024, where PLENET/GRIMBOLT served as a cross-platform .NET Core implant. Most reporting overlooks how these actors systematically map proprietary appliance persistence mechanisms—customized per device—to enable long-term C2 via proxying that blends with legitimate traffic. The 18-month dwell time and MSP vector underscore supply-chain exposure in managed services, where firewall and NAS compromises provide durable footholds for M365 access without triggering Conditional Access policies. This evolution from Windows-centric operations to Linux/BSD appliances reflects broader Chinese cyber doctrine prioritizing stealthy infrastructure control over flashy ransomware.
[SENTINEL]: VerdantBamboo's appliance focus will accelerate targeting of edge devices like routers and NAS in Western critical infrastructure, creating persistent backdoors that bypass traditional network defenses.
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html)
- [2]Volexity Technical Report on VerdantBamboo(https://www.volexity.com/blog/2026/verdantbamboo-brickstorm-bsd/)
- [3]Google Threat Analysis on UNC6201 and PLENET(https://blog.google/threat-analysis-group/unc6201-dell-recoverpoint/)