🌐 Nation-State Threats

UNC6201's Dell RecoverPoint Zero-Day: BRICKSTORM Dies, GRIMBOLT Rises

Thought BRICKSTORM was the worst? UNC6201 just leveled up to GRIMBOLT on Dell's RecoverPoint zero-day. Your virtual machines are in the crosshairs.

Mandiant diagram showing UNC6201 exploitation chain from Dell RecoverPoint to GRIMBOLT backdoor

⚡ Key Takeaways

  • UNC6201 exploited Dell RecoverPoint zero-day CVE-2026-22769 since mid-2024 for lateral movement and persistence. 𝕏
  • Swapped BRICKSTORM for evasive GRIMBOLT malware, using native AOT compilation to thwart analysis. 𝕏
  • New TTPs include Ghost NICs and iptables SPA for VMware pivoting, signaling deeper virtual infra threats. 𝕏
Published by

theAIcatchup

Threat intelligence. Zero noise.

Worth sharing?

Get the best Cybersecurity stories of the week in your inbox — no noise, no spam.

Originally reported by Mandiant Blog

Stay in the loop

The week's most important stories from theAIcatchup, delivered once a week.