<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks-1pffgypwt" -->

---
title: Chinese APT deploys new malware to keep access to hacked...
description: Chinese espionage group UNC5221 (also tracked as VerdantBamboo) has been using the Brickstorm backdoor alongside two newly documented malware strains — Plenet...
canonical: https://daily.dev/posts/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks-1pffgypwt
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Chinese APT deploys new malware to keep access to hacked networks | daily.dev
og:description: Chinese espionage group UNC5221 (also tracked as VerdantBamboo) has been using the Brickstorm backdoor alongside two newly documented malware strains — Plenet...
og:url: https://daily.dev/posts/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks-1pffgypwt
og:image: https://api.daily.dev/og/posts/1PfFgYpWt.png
og:image:alt: Chinese APT deploys new malware to keep access to hacked networks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Chinese APT deploys new malware to keep access to hacked networks

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

Chinese espionage group UNC5221 (also tracked as VerdantBamboo) has been using the Brickstorm backdoor alongside two newly documented malware strains — Plenet and AgentPSD — to maintain persistent access to victim networks, including Microsoft 365 environments. Volexity's investigation revealed the threat actor had been present for at least 18 months before detection, compromised the victim's MSP as a pivot point, and re-established access even after remediation. Plenet is a cross-platform .NET backdoor with WebSocket-based C2, while AgentPSD is a Python reverse shell used as a fallback persistence mechanism. The group targets edge devices and systems lacking EDR support, blending in with legitimate traffic to evade detection. IOCs have been published on GitHub.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks>

---

Tags: [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks-1pffgypwt)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Chinese APT deploys new malware to keep access to hacked networks","url":"https://daily.dev/posts/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks-1pffgypwt","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks-1pffgypwt"},"datePublished":"2026-06-05T18:10:32.080Z","dateModified":"2026-06-05T18:11:00.692Z","description":"Chinese espionage group UNC5221 (also tracked as VerdantBamboo) has been using the Brickstorm backdoor alongside two newly documented malware strains — Plenet...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ee89cf1329b25f9a65f5c61ab1e0f340?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ee89cf1329b25f9a65f5c61ab1e0f340?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks-1pffgypwt","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Chinese APT deploys new malware to keep access to hacked networks"}]}
```

