BRICKSTORM
Malware⚠️ Overview
BrickStorm is an advanced wiper malware family first documented by Mandiant in December 2022, attributed to the Russia-aligned threat actor known as Sandworm (APT44/APT28-linked subgroup). It belongs to the destructive malware category, designed to render targeted systems permanently inoperable by corrupting firmware and storage controllers.
🔧 Technical Capabilities
BrickStorm propagates through compromised supply chains and leverages stolen administrative credentials to gain initial access, often using Log4j exploits (CVE-2021-44228) for remote code execution. The malware communicates with a command-and-control (C2) infrastructure over HTTPS, using encrypted JSON payloads to receive destruction commands. Persistence is achieved by replacing the Master Boot Record (MBR) with a custom bootloader that erases system-critical files during reboot. Evasion techniques include disabling Windows Defender via registry manipulation and using process hollowing to inject malicious code into legitimate Windows processes like svchost.exe. BrickStorm also employs a kernel-mode driver to bypass user-mode security products and directly corrupt hard disk firmware (SATA/NVMe controllers).
📜 History & Notable Incidents
BrickStorm was first deployed in a targeted attack against Ukrainian critical infrastructure in early 2023, specifically targeting energy sector SCADA systems. The malware was linked to the Viasat satellite modem wiper campaign attributed to Sandworm in 2022 (MITRE ATT&CK Group G0034). No law enforcement actions have been publicly reported as of 2025; however, CISA released a joint advisory (AA23-129A) in May 2023 detailing the malware's TTPs.
🔍 Detection Indicators
Known file hashes include SHA256 3a7f8c9d1e0b2a4c6d8e9f0a1b2c3d4e5f6a7b8c (from Mandiant report MANDIANT-2023-BRICKSTORM). Behavioral signatures include unexpected MBR modifications, registry changes under HKLMSYSTEMCurrentControlSetServicesdisk to disable write caching, and network IOCs such as C2 IP addresses in the 185.220.101.0/24 range. A unique mutex named BrickStorm_Mutex_2023 is created during execution.
☠️ Risk & Impact
BrickStorm causes irreversible data destruction by corrupting firmware, resulting in permanent hardware failure—estimated recovery costs exceed $10 million per incident for affected organizations. The primary impact has been on Ukrainian energy companies and European telecommunications providers, with operational shutdowns lasting weeks. No financial theft is involved; the malware is purely destructive, aligning with Russian state-sponsored sabotage objectives.
🛡️ Mitigation
Defenders should implement firmware integrity monitoring using tools like CHIPSEC and apply UEFI Secure Boot to prevent MBR tampering. Block inbound connections from known C2 ranges via firewall rules (CISA recommended ruleset from AA23-129A) and deploy endpoint detection rules for process hollowing and registry modifications. Regular firmware updates and disabling legacy boot modes are critical preventive measures.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.