A China-nexus cyber espionage outfit has been seen targeting Linux computers with two different malware families dubbed PLENET (also known as GRIMBOLT) and AGENTPSD, as well as a BSD variation of a known backdoor called BRICKSTORM.
Volexity has linked the activity to a threat cluster it monitors called VerdantBamboo, which it claims overlaps with hacker groups including Warp Panda (CrowdStrike), UNC5221 (Google), and Clay Typhoon (Microsoft).
The cybersecurity firm claimed to have found the breach during an incident response engagement in September 2025, when it became clear that the adversary had penetrated the Egnyte Storage Sync system of an unidentified victim by using a local privilege escalation flaw to deploy BRICKSTORM. Storage Sync version 13.13, which was made available in March 2026, fixed the problem.
In a technical study released last week, researchers Damien Cash, Paul Rascagneres, Steven Adair, and Tom Lancaster stated that VerdantBamboo had occasionally accessed the appliance using IP addresses read more about VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
