Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Hunting BRICKSTORM Backdoor in VMware vCenter Backups

Rubrik
05/11/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


There are a lot of urgent security advisories going around every day, but when you find one that gets talked about frequently and references core infrastructure components in your environment, it's definitely time to take notice. But how will you know if your organization may be facing one of these critical, active threats? Recently, Rubrik Zero Labs issued a high-priority advisory for Brickstorm because our systems have already flagged files in our customers' vCenter backups that match its indicators of compromise. This signifies a high probability of compromise by the espionage actor UNC-5221, as detailed in public reporting from Google's Threat Intelligence team. This backdoor is extremely stealthy, designed to evade detection by targeting systems like vCenter appliances that typically don't run endpoint protection tools and masquerading as legitimate processes. The most dangerous part? This backdoor could be living in your backups, waiting to be restored and reopen the attacker's foothold. Today, I'm going to show you how you can use the Rubrik Security Cloud to identify this threat, contain it, and put yourself on the road to recovering vCenter to a state prior to the existence of the threat. First, we need to find every instance of this threat across our recovery points. From the Rubrik dashboard, we'll navigate to Data Threat Analytics, and then select the Hunts tab. Here, we click Start Threat Hunt, and select Advanced Threat Hunt, which will give us a more thorough investigation. And then we select our vCenter servers. Now for the most important part, adding the indicators of compromise from the guidance document. Google provided nine YAR rules. It's important to add these individually, but we'll use the magic of video editing to speed up this process. Google also provided three file hash values, which we can add alongside the YAR rules. Fortunately, we can paste in all three hashes as a comma-delimited group. After naming this hunt, we can define how far back we want to scan. These advanced threat hunts can take some time, so we'll start by searching back one week. We can always go back further with another hunt later. We'll also set some limits to help it run faster. For Brickstorm, we'll want to search for all IOCs, but can limit the size of files, essentially skipping over anything over 1.5 megabytes. We'll also explicitly include all files. And now we can start our threat hunt. The hunt is complete, and as you can see, we have one object that matched our IOCs, confirming the threat is present in the backups of one of our vCenter servers. Our immediate priority is containment. We cannot allow these infected backups to be used for any type of restore. We must quarantine all snapshots taken within this time range. Right from this results screen, I can select an infected snapshot and apply a quarantine. This action immediately locks the snapshot, preventing anyone without permission from accidentally restoring the attacker's backdoor into our production environment. Now that we've contained the threat, we need to recover. We'll export it as a new virtual machine. And by selecting the non-quarantine and non-anomalous, we can see that it's picking the most recent version that was not infected. With RBAC permissions in place, there is less risk of accidentally reintroducing the backdoor. There are a number of variables that need to be considered for how to recover and how much data you can afford to lose. In some cases, you may need to restore individual files from a more recent snapshot into a clean install or older recovery. We recommend following Broadcom's documentation, working with Rubrik support and our ransomware response team, and any other incident response teams your company works with. Fortunately, Rubrik will also quarantine at the file level the affected files. Whichever recovery path you take, Rubrik tried to make it easy to get back to clean. By using Rubrik Advanced Threat Hunting, we were able to find a highly elusive threat inside our backups, quarantine the infected snapshots, and most importantly, identify a guaranteed clean snapshot to enable a fast and safe recovery. This is how Rubrik turns your backup data from a safety net into a strategic asset for cyber resilience. Thanks for watching. For more information, please visit rubrik.com.

TL;DR

  • BRICKSTORM backdoor targets VMware vCenter appliances and can persist in backup snapshots, creating reinfection risk during recovery operations if compromised backups are restored.
  • Rubrik Security Cloud enables proactive threat hunting across backup repositories using YARA rules and file hashes, scanning historical recovery points to identify infected snapshots before restoration.
  • Infected snapshots can be immediately quarantined through RBAC-controlled actions, preventing accidental restoration while identifying the most recent clean recovery point for safe restoration operations.

Summary

This demonstration addresses the BRICKSTORM backdoor threat targeting VMware vCenter environments, showing how Rubrik Security Cloud enables proactive threat detection within backup data. The video walks through the complete workflow for identifying compromised vCenter backups using YARA rules and file hash indicators of compromise provided by Google's Threat Intelligence team. BRICKSTORM, associated with espionage actor UNC5221, is particularly dangerous because it targets infrastructure components that typically lack endpoint protection and can persist in backup snapshots, creating a reinfection risk during recovery operations. The demo illustrates how Rubrik's Advanced Threat Hunting capability scans historical recovery points, quarantines infected snapshots to prevent accidental restoration, and identifies clean recovery points for safe restoration. This approach transforms backup repositories from passive storage into active security assets, enabling organizations to detect threats that evade traditional security tools and recover to verified clean states. The workflow emphasizes containment through snapshot quarantine and strategic recovery planning in coordination with incident response teams and vendor guidance.

Chapters

0:00 - BRICKSTORM Threat Overview
1:11 - Initiating Advanced Threat Hunt
1:33 - Adding Indicators of Compromise
2:25 - Quarantining Infected Snapshots
3:01 - Clean Recovery Strategy

Key Quotes

0:20 "Recently, Rubrik Zero Labs issued a high-priority advisory for Brickstorm because our systems have already flagged files in our customers' vCenter backups that match its indicators of compromise."
0:54 "The most dangerous part? This backdoor could be living in your backups, waiting to be restored and reopen the attacker's foothold."
4:08 "This is how Rubrik turns your backup data from a safety net into a strategic asset for cyber resilience."

Categories:
  • » Webinar Library » Rubrik
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Threat Intelligence
  • Demo
  • Technical Deep Dive
  • Backup & Recovery
  • Security Operations
  • Advanced Persistent Threats
  • VMware vCenter Security
  • Backup-Based Threat Detection
  • YARA Rule Scanning
  • Snapshot Quarantine
  • Cyber Resilience
  • Incident Response
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Hunting BRICKSTORM Backdoor in VMware vCenter Backups

              Upcoming Webinar Calendar

              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                Preventing Your AI from Turning Against You: Essential Strategies
                https://www.truthinit.com/index.php/channel/2021/preventing-your-ai-from-turning-against-you-essential-strategies/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Resilience Insights from Hybrid Threats Amidst Cloud Challenges
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-amidst-cloud-challenges/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Manifesting Agentic Trust in Real Life
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-manifesting-agentic-trust-in-real-life/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Quality Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-quality-security-team-for-unmatched-defense/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers During the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-during-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Insights and Strategies from the DPDP Webinar
                https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-from-the-dpdp-webinar/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 08/19/2026
                12:00 PM
                08/19/2026
                Witness Cyera Agent Security in Action: A Firsthand Experience
                https://www.truthinit.com/index.php/channel/2036/witness-cyera-agent-security-in-action-a-firsthand-experience/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                30

                Mastering Active Directory Certificate Services for Long-Term Success

                06/30/202601:00 PM ET
                • Jul
                  01

                  Integrating Security in AI: Automated Red Teaming Strategies for Private Models

                  07/01/202604:00 AM ET
                  • Jul
                    01

                    Schutz von KI in Anwendungen, Agenten und APIs.

                    07/01/202604:00 AM ET
                    • Jul
                      01

                      Preventing Your AI from Turning Against You: Essential Strategies

                      07/01/202601:00 PM ET
                      • Jul
                        02

                        Resilience Insights from Hybrid Threats Amidst Cloud Challenges

                        07/02/202610:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version