Malicious BRICKSTORM Backdoor Execution via Masqueraded Binary Path

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-08-20
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects execution of the BRICKSTORM backdoor from masqueraded system paths used by the VerdantBamboo intrusion set. The malware was deployed as /usr/sbin/luserput and as a blacklist binary under the IPSec libexec directory on pfSense firewalls to blend with legitimate appliance components. Detecting these hardcoded drop locations exposes an active foothold on network edge devices used for long-term espionage.

Related detections9 linkedT1543 — drag to rearrange
Suspicious SonicWall SMA init.d Persistence Launching deploy_new.py
Malicious Linux XorDDoS gcc.pid Device Marker File via file_event
Windows Code Integrity: Blocked Driver Load Due to Revoked Certificate (Event ID 3023)
Windows PUA System Informer Driver Load via SystemInformer.sys
System Informer Execution on Windows Process Creation
Windows Driver Load: Process Hacker (processhacker.sys) Presence
Windows Code Integrity blocked image/driver loads due to signature level or policy violations
Windows Process Hacker Execution Identified by Image Metadata and Hashes
Windows: Service Created by System Using Client with PID 0 (SCM Event 7045)
Malicious BRICKSTORM Backdoor Execution via Masqueraded Binary Path
Pivot detection · T1543 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.