What Happened
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems. The activity has been attributed by Volexity to a threat cluster it tracks as VerdantBamboo, which it said overlaps with hacking groups known as Clay Typhoon (Microsoft),
Why It Matters
The article reports that the China-linked VerdantBamboo threat cluster deployed a BSD variant of the BRICKSTORM backdoor, along with PLENET and AGENTPSD malware, to compromise Linux-based edge appliances such as pfSense firewalls and NAS/storage systems, including via a managed service provider’s infrastructure.[1][2] Volexity found the group exploiting local privilege escalation, misconfigured sudo rules, and the limited monitoring on appliances to maintain long-term, stealthy access across multiple environments.[1][2] From a CyberSE.AI perspective, this highlights a critical AI and IT supply chain risk: the same appliance and MSP blind spots exploited by VerdantBamboo for infrastructure access could be used to gain indirect control over AI workloads, models, and data that transit or depend on those network devices. Organizations should treat firewalls, storage sync systems, NAS, and MSP-managed appliances as part of their AI supply chain, enforcing strong hardening, MFA, configuration review, SBOM-driven patching, and compensating monitoring controls to prevent stealthy compromise that could later be leveraged against AI systems and agents.
CyberSE Analysis
This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html