China-linked APT weaponized Dell RecoverPoint zero-day since 2024

4 Min Read

A suspected Chinese state-linked group exploited a critical Dell RecoverPoint flaw (CVE-2026-22769) in zero-day attacks starting mid-2024.

Mandiant and Google’s Threat Intelligence Group (GTIG) reported that a suspected China-linked APT group quietly exploited a critical zero-day flaw in Dell RecoverPoint for Virtual Machines starting in mid-2024.

- Advertisement -

“Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769, with a CVSSv3.1 score of 10.0.” reads the report published by Google. “Analysis of incident response engagements revealed that UNC6201, a suspected PRC-nexus threat cluster, has exploited this flaw since at least mid-2024 to move laterally, maintain persistent access, and deploy malware including SLAYSTYLEBRICKSTORM, and a novel backdoor tracked as GRIMBOLT.”

The vulnerability, tracked as CVE-2026-22769, involves hardcoded credentials and was abused to gain access to VMware backup systems.


What do you think? Post a comment.


“Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.” reads the advisory published by Dell.”Dell has received a report from Google/Mandiant of limited active exploitation of this vulnerability. Dell strongly recommends that customers apply one of the remediations below to address this vulnerability as soon as possible.”

- Advertisement -

EXPLORE MORE

Wanted: Suspects for Shooting Incident in the 22nd District [VIDEO]

The Philadelphia Police Department and the Shooting Investigation Group is asking for…

Was Gloria Steinem a CIA agent working to overthrow the family?

Top feminist Gloria Steinem who died this week at age 92 may…

From Track Star to WWE Champion: Inside Lainey Reid’s Rise to the Top

Whether she’s dominating in the ring on WWE’s SmackDown or holding gold…

Wanted: Suspects for Shooting Incident in the 39th District [VIDEO]

The PPD Northwest Detective Division is attempting to identify the individuals responsible…

Why Can’t Pandas Get It On? The Answer to Their Poor Sex Lives May Lie in Their Intestines

Poor pandas. While the iconic bear species of China is no longer…

Missing Persons Ka’mya Adams (Right) and Brianna Adams (Left) from the 15th District Have Been Located

The Philadelphia Police Department is seeking the public’s assistance in locating the…

The China-nexus group exploited the bug to move laterally, maintain persistence, and deploy malware such as SLAYSTYLE, BRICKSTORM, and a new C# backdoor, GRIMBOLT. Researchers observed advanced tactics, including stealthy VMware pivoting via “Ghost NICs” and Single Packet Authorization with iptables. Dell has released patches and mitigation guidance.

During investigations into compromised Dell RecoverPoint appliances, Mandiant researchers discovered that attackers replaced BRICKSTORM with a new C# backdoor, GRIMBOLT, in September 2025. GRIMBOLT is compiled using Native AOT and packed with UPX. The malware provides remote shell access and reuses BRICKSTORM’s command-and-control channels.

“It provides a remote shell capability and uses the same command and control as previously deployed BRICKSTORM payload.” continues the report. “It’s unclear if the threat actor’s replacement of BRICKSTORM with GRIMBOLT was part of a pre-planned life cycle iteration by the threat actor or a reaction to incident response efforts led by Mandiant and other industry partners.”

The attackers ensured persistence by modifying a legitimate startup script so the backdoor runs automatically at boot.

While investigating compromised Dell RecoverPoint systems, Mandiant uncovered CVE-2026-22769 after spotting Tomcat Manager access using hardcoded admin credentials. Attackers uploaded a malicious WAR file containing the SLAYSTYLE web shell, gaining root command execution as early as mid-2024. The group also expanded into VMware environments, creating “Ghost NICs” for stealthy lateral movement and using iptables-based Single Packet Authorization to covertly redirect and control traffic on vCenter appliances.

Google released Indicators of Compromise (IOCs) and Yara rules for this campaign.

Pierluigi Paganini



Share This Article

Bill Adair: The Evolution, Methodologies, and Criticisms of Modern Fact-Checking

Bill Adair, the Knight Professor of the Practice of…

The Songwriter Who Taught America How to Love: Remembering Dolly Parton

There are rare figures in American culture who do…

CIA Director Pushed Trump-Putin-Zelensky Summit During Moscow Visit: Report

Yet another take has been issued, and more alleged…

US seeks next leader of Cuba

Washington is reportedly seeking to repeat the Venezuela scenario…

Cassandra Peterson: Life Beyond the Bouffant for the Queen of Halloween

For over four decades, Cassandra Peterson has reigned supreme…

Architect of Empire, Harbinger of Famine: The Legacy of Sir Charles Trevelyan

Sir Charles Edward Trevelyan, 1st Baronet (1807–1886) stands as…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted