pfSense Firewall Compromised in VerdantBamboo Cyberattack Deploying BRICKSTORM

VerdantBamboo hackers compromised a pfSense firewall and deployed a FreeBSD variant of the BRICKSTORM backdoor, giving the threat actor long-term access to a managed service provider’s network.

The activity was uncovered during a Volexity incident response investigation, which linked the attack to a wider campaign targeting edge devices and systems with limited security monitoring.

The investigation began after suspicious traffic was found coming from a Linux-based Egnyte Storage Sync virtual appliance.

Instead of connecting only to trusted Egnyte services, the system was communicating with attacker-controlled infrastructure hidden behind Cloudflare IP addresses.

Volexity later found that the appliance had been infected with BRICKSTORM, a remote access Trojan used by VerdantBamboo.

The attackers used valid credentials and proxy features in the malware to access the victim’s Microsoft 365 environment. This helped them blend into normal network traffic and bypass Conditional Access rules.

VerdantBamboo Breaches pfSense Firewall

Further analysis showed the compromise had existed for at least 18 months. After the initial cleanup, VerdantBamboo returned using stolen administrative credentials to access the victim’s firewall.

The attackers enabled web SSL VPN access, used it to reconnect to the internal network, and deployed more malware on a Synology NAS device.

During the same investigation, Volexity also examined the victim’s managed service provider. Researchers found that the MSP’s pfSense firewall had been compromised by VerdantBamboo.

The attackers deployed a BSD-compatible BRICKSTORM implant named blocklist under the /usr/local/libexec/ipsec/ directory. They also modified /etc/rc.d/cron to execute the implant and maintain persistence.

BRICKSTORM is a powerful backdoor written mainly in Golang, with later variants also seen in Rust. It supports remote command execution, SOCKS5 proxying, and file system access through a web interface.

These features allow attackers to move inside networks, hide traffic, and reach cloud services through trusted systems.

SectionDetails
TitlepfSense Firewall Compromised in VerdantBamboo Cyberattack Deploying BRICKSTORM
Threat ActorVerdantBamboo, also tracked as WARP PANDA and UNC5221
TargetMSP’s pfSense firewall and victim organization’s edge systems
Malware UsedBRICKSTORM backdoor, AGENTPSD, and PLENET/GRIMBOLT
Main FindingVerdantBamboo deployed a FreeBSD-compatible BRICKSTORM implant on a pfSense firewall.
Persistence MethodAttackers modified /etc/rc.d/cron to execute the implant automatically.

Volexity also identified two additional malware families. AGENTPSD is a basic Python reverse shell used as a backup access method. PLENET, also tracked as GRIMBOLT, is a .NET Native AOT backdoor deployed on Linux-based systems.

The campaign shows how advanced threat actors are targeting firewalls, storage appliances, VPN systems, and NAS devices because they often lack endpoint detection and response coverage.

Organizations should restrict internet-facing admin panels, enforce MFA on local and administrative accounts, review VPN access, monitor unusual outbound traffic, and inspect edge devices for unauthorized files, cron changes, and unknown binaries.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post pfSense Firewall Compromised in VerdantBamboo Cyberattack Deploying BRICKSTORM appeared first on Cyber Security News.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading