:

CHINESE APT DEPLOYS NEW MALWARE TO MAINTAIN NETWORK ACCESS

SECURITY DESK2 MIN READ
SUN, JUN 7, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor alongside two previously undocumented malware variants named Plenet and AgentPSD.

Security researchers have identified UNC5221, a Chinese advanced persistent threat (APT) group, actively deploying multiple malware tools to establish and maintain unauthorized access to compromised networks. The group leverages Brickstorm, a known backdoor, in combination with two newly discovered malware families. Plenet and AgentPSD represent previously undocumented threats designed to provide persistent access mechanisms within compromised Microsoft 365 environments. Attack Strategy The deployment of multiple malware variants suggests a layered approach to maintaining network persistence. By combining known and unknown tools, UNC5221 increases the likelihood that traditional security defenses will fail to detect and remove all access points, even if one malware family is discovered and remediated. Target Profile The focus on Microsoft 365 environments indicates the group targets organizations relying on cloud-based productivity suites. These systems often contain sensitive business communications, financial data, and intellectual property. Detection Challenge The existence of previously undocumented malware variants complicates detection efforts. Organizations relying solely on signature-based detection may miss these threats. The simultaneous use of multiple tools increases the technical complexity of incident response and remediation efforts. Implications The discovery highlights persistent threats from state-sponsored Chinese threat actors targeting cloud infrastructure. Organizations should assume that defensive measures focusing on perimeter security alone are insufficient. The group's sophistication in deploying custom malware indicates significant resources and development capabilities. Recommendations Security teams should prioritize comprehensive logging and monitoring of Microsoft 365 access patterns, implement multi-factor authentication across cloud environments, and conduct thorough investigation of any suspicious account activities. Threat intelligence sharing about Plenet and AgentPSD signatures will aid broader industry defense efforts.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

U.S. military branches have disabled advertising trackers on government-issued phones and computers following reports that location data from these trackers was being used to target American forces in the Middle East.

JUST NOWIndustry Desk

At least 14 people across Serbian civil society were infected with advanced spyware in what digital rights group Share Foundation calls the country's largest documented surveillance wave. Student protesters were among those targeted, though the government of Aleksandar Vučić denies involvement.

1H AGOSecurity Desk

An identity verification company left its systems exposed, allowing hackers real-time access to scan data for over 12 months. The breach potentially affected millions of users whose identification documents were processed through the platform.

1H AGOSecurity Desk

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives.

12H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.