ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

China-linked hackers exploited Dell zero-day since 2024 (CVE-2026-22769)

criticalExploit / PoCimportance 60CVE-2026-22769

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-22769
Hard-coded credentials in Dell RecoverPoint for Virtual Machines allow root OS access

Dell RecoverPoint for Virtual Machines (RP4VMs) versions prior to 6.0.3.1 HF1 contain hard-coded credentials (CWE-798) for the appliance's underlying operating system. An unauthenticated remote attacker who knows the hard-coded credential can authenticate over the network with no user interaction and gain root-level access and persistence on the underlying OS — beyond just the RecoverPoint application — which is why the flaw scores a maximum CVSS of 10.0 with scope changed. Any organization running an affected RP4VMs release is exposed, with risk highest where appliance management interfaces are reachable from broader networks. The vulnerability is confirmed exploited in the wild: it was added to CISA's KEV catalog on 2026-02-18, and reporting indicates China-linked actors exploited it as a zero-day since at least 2024, prompting an emergency federal patch directive; related coverage ties the activity to the China-linked VerdantBamboo actor deploying BRICKSTORM-family backdoors on appliances.

Do: Upgrade all RP4VMs appliances to 6.0.3.1 HF1 or apply Dell's published remediations immediately — federal agencies must patch per BOD 22-01 by the KEV deadline (reported as 'by Saturday'). Because exploitation has occurred since at least 2024, treat deployed appliances as potentially compromised: review the underlying OS for unexpected accounts, modified services, and root persistence, and restrict the appliance's management/replication network reachability until patched.

10.013% KEV
  • Dell RecoverPoint for Virtual Machines (RP4VMs) All versions prior to 6.0.3.1 HF1
moderate≈ tens of thousands of appliances worldwide (estimated from deployment patterns; internet-exposed count unknown)
Full article550 words · extracted from helpnetsecurity.com · click to collapse

A suspected China-linked cyberespionage group has been covertly exploiting a critical zero-day flaw (CVE-2026-22769) in Dell’s RecoverPoint for Virtual Machines software since at least mid-2024, according to new research from Google’s threat intelligence team and Mandiant.

The attackers deployed stealthy backdoors (BRICKSTORM and GRIMBOLT), a webshell (SLAYSTYLE) and maintained long-term access inside targeted networks.

“Beyond the Dell appliance exploitation, Mandiant observed the actor employing novel tactics to pivot into VMware virtual infrastructure, including the creation of ‘Ghost NICs’ [i.e., Network Interface Cards] for stealthy network pivoting and the use of iptables for Single Packet Authorization (SPA),” the researchers shared on Tuesday.

They tied the attacks to UNC6201, a suspected PRC-nexus threat cluster that shows “notable overlaps” with UNC5221, a Chinese threat actor that’s often conflated with Silk Typhoon (“although GTIG does not currently consider the two clusters to be the same.)

Default credentials exposed Dell backup systems to compromise

The analysts were unable to pinpoint how the attackers achieved initial access to affected systems, but UNC6201 is known to target edge appliances. (UNC5221 as well.)

Mandiant incident responders discovered CVE-2026-22769 while investigating hacked Dell RecoverPoint systems inside a victim’s network, after they noticed the systems were communicating with hacker-controlled command and control servers associated with BRICKSTORM and GRIMBOLT backdoors.

“During analysis of the appliances, analysts identified multiple web requests to an appliance prior to compromise using the username admin. These requests were directed to the installed Apache Tomcat Manager, used to deploy various components of the Dell RecoverPoint software, and resulted in the deployment of a malicious WAR file containing a SLAYSTYLE web shell,” they explained.

“After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager, upload a malicious WAR file using the /manager/text/deploy endpoint, and then execute commands as root on the appliance.”

The BRICKSTORM backdoor is a known threat, wielded by UNC5221 and related threat clusters, and deployed on appliances that do not support traditional endpoint detection and response (EDR) tools. This allows the attackers to keep their presence in target organizations’ networks quiet.

According to Mandiant and GTIG, the GRIMBOLT backdoor is built in a way that turns it directly into machine code before it’s run, which makes it easier to run on small devices and harder to detect via static analysis. The attackers edited a legitimate shell script to launch the backdoor each time the script is run.

“It’s unclear if the threat actor’s replacement of BRICKSTORM with GRIMBOLT was part of a pre-planned life cycle iteration by the threat actor or a reaction to incident response efforts led by Mandiant and other industry partners,” the analysts added.

Remediation and investigation

Dell has provided instructions on how to remediate CVE-2026-22769, and Mandiant and GTIG have provided indicators of compromise, outlined artifacts that point to Dell RecoverPoint compromise, and shared YARA rules for detecting the presence of the GRIMBOLT backdoor and the SLAYSTYLE webshell.

Earlier this month, CISA revised its report on the BRICKSTORM backdoor with the latest indicators of compromise related to the threat.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/02/18/exploited-dell-zero-day-cve-2026-22769-brickstorm-grimbolt/