# China-Linked VerdantBamboo Deploys Advanced Malware Arsenal on Linux Appliances Through MSP Supply Chain


## The Threat


A sophisticated China-nexus cyber espionage group tracked as VerdantBamboo has been conducting a sustained campaign deploying multiple malware families—including a newly observed BSD variant of the BRICKSTORM backdoor—against Linux appliances and network storage devices. Researchers at Volexity discovered the intrusion during incident response work in September 2025, revealing an attack chain that exploited both direct network access and compromised service provider infrastructure to establish persistent remote access within target organizations.


The campaign demonstrates a deliberate shift in adversary tactics toward environments where endpoint detection and response (EDR) software is typically absent. Rather than targeting traditional workstations and servers, VerdantBamboo operators focused their efforts on Egnyte Storage Sync appliances, pfSense firewalls, and Synology NAS devices—systems that are frequently overlooked by defenders but critically positioned for lateral movement and data access. The threat actor chained together local privilege escalation exploits, credential theft, and sophisticated malware deployment to bypass network segmentation and gain access to sensitive environments, including Microsoft 365 infrastructure.


What makes this campaign particularly concerning is the evidence of supply chain compromise. Volexity's investigation revealed that the victim organization was initially breached through a compromise of their Managed Services Provider (MSP), where attackers had already deployed BRICKSTORM on a pfSense firewall gateway. This positioned the threat actor to pivot from the MSP infrastructure directly into the downstream victim organization, a tactic that suggests VerdantBamboo is deliberately targeting MSPs as force multipliers for accessing multiple customers simultaneously.


## Severity and Impact


| Attribute | Details |

|-----------|---------|

| Threat Group | VerdantBamboo (aka Clay Typhoon, UNC5221, Warp Panda) |

| Campaign Duration | At least 18 months of undetected access |

| Initial Compromise Vector | Egnyte Storage Sync Local Privilege Escalation |

| Affected Platform | Linux, BSD, .NET Core, Python environments |

| Attack Complexity | High (requires compromise of privileged infrastructure or MSP) |

| Authentication Required | No (for initial appliance exploitation); Yes (for lateral movement) |

| Primary Objective | Persistent remote access, credential harvesting, lateral movement |

| Dwell Time (Undetected) | Approximately 18+ months |


The sustained nature of the intrusion—lasting at least 18 months before discovery—underscores the gaps in monitoring and detection for non-traditional infrastructure. The attacker's ability to return after initial remediation, using stolen administrative credentials, indicates both operational discipline and deep reconnaissance of the victim's network architecture.


## Affected Products


Direct Victims:

  • Egnyte Storage Sync (versions prior to 13.13)
  • Synology Network Attached Storage (NAS) devices
  • pfSense firewalls (when deployed in MSP environments)

  • Wider Risk:

  • Any organization using MSP services that manage firewalls, VPNs, and network infrastructure
  • Microsoft 365 environments accessible through compromised storage appliances
  • Linux-based appliances lacking dedicated EDR monitoring
  • Organizations with web SSL VPN access controlled by potentially compromised firewall administrators

  • Related Historical Context:

  • Dell RecoverPoint for Virtual Machines (affected by CVE-2026-22769, CVSS 10.0, exploited by related groups)

  • ## Mitigations


    Immediate Actions:

  • Update Egnyte Storage Sync to version 13.13 or later immediately
  • Audit all administrative credentials with access to firewalls, VPNs, and storage appliances
  • Review pfSense, Synology, and appliance firewall logs for unauthorized configuration changes, especially web SSL VPN modifications
  • Implement network segmentation to isolate management interfaces from general network traffic

  • Detection and Response:

  • Hunt for BRICKSTORM, PLENET (GRIMBOLT), and AGENTPSD across Linux systems and appliances
  • Monitor for SSH authentication to NAS devices and network appliances from unexpected sources
  • Search for outbound connections to suspicious domains and IP addresses associated with VerdantBamboo
  • Investigate any instances where VPN profiles were modified or new SSL VPN access was configured

  • Supply Chain Risk:

  • Conduct comprehensive audits of your MSP's security posture, specifically around firewall and VPN infrastructure
  • Request logs from your MSP covering the past 18+ months for any suspicious administrative activity
  • Implement conditional access policies in Microsoft 365 to detect and block access from compromised network appliances
  • Require multi-factor authentication for administrative access to all network infrastructure

  • Long-Term Hardening:

  • Deploy dedicated monitoring solutions on appliances and network devices that cannot run traditional EDR software
  • Implement anomaly detection for unusual command execution and file modifications on Linux-based appliances
  • Establish immutable audit logging for all administrative actions on critical network infrastructure

  • ## References


  • Volexity Technical Report: VerdantBamboo Campaign Analysis (June 2026)
  • Google Threat Intelligence Report: UNC6201 and PLENET Deployment (February 2026)
  • Egnyte Security Advisory: Storage Sync Version 13.13 Release Notes (March 2026)

  • ## HackWire Analysis


    VerdantBamboo's campaign reveals a critical blindspot in enterprise security: the underdefended perimeter of network appliances and MSP-managed infrastructure. While organizations have invested heavily in endpoint detection and EDR solutions for traditional compute environments, they've left the "invisible infrastructure"—firewalls, storage appliances, VPN concentrators, and NAS devices—almost entirely unmonitored.


    This isn't a coincidence. VerdantBamboo is demonstrating genuine operational sophistication: they've mapped where defenders typically *don't* look, and they're exploiting that asymmetry. The BSD variant of BRICKSTORM is particularly significant because it signals the group's capability to adapt their tooling across Unix-like environments. This breadth of platform support, combined with custom persistence mechanisms tailored to specific devices, indicates a threat actor with deep infrastructure knowledge and substantial development resources.


    The supply chain angle deserves particular attention. Too many organizations treat their MSP relationship as a trust boundary without enforcing the same security controls they would on their own network. VerdantBamboo's approach of compromising pfSense firewalls in the MSP infrastructure to access downstream victims is a proven playbook that works because MSP security is notoriously inconsistent. Organizations need to demand formal security attestations, log access, and implement zero-trust principles even when delegating infrastructure management to third parties.


    The 18-month dwell time also highlights the detection gap. Modern threat intelligence and forensics can now surface these campaigns, but only after the fact and only when organizations have the resources to conduct deep incident response. The real winners here will be defenders who shift from purely reactive hunting to proactive appliance monitoring and more rigorous network access controls at the VPN layer. If VerdantBamboo can't get through the firewall, they can't compromise the MSP; if they can't compromise the MSP, they can't access the downstream victim.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)