U.S. Law Firms Face Cyberattacks From Suspected China-Linked Hackers, Google Warns

Google and Mandiant warn that UNC5221, a suspected China-linked group, is targeting U.S. law firms using BRICKSTORM malware to steal sensitive data for espionage.

Key points:

  • Google and Mandiant identify UNC5221 as an espionage group targeting U.S. law firms.
  • Hackers deploy BRICKSTORM malware to maintain long-term access to systems.
  • Average dwell time is 393 days, far above the global average of 10 days.
  • Intrusions focus on national security, international trade, and intellectual property.

U.S. law firms are facing cyberattacks from a hacking group with suspected links to China, according to a warning issued by Google’s Threat Intelligence Group and Mandiant. The campaign, attributed to a group identified as UNC5221, employs a backdoor known as BRICKSTORM to maintain persistent access to compromised systems.

The attackers’ primary objective is espionage. They focus on national security, trade, and intellectual property matters by infiltrating law firms, technology providers, and other industries. “The targeting of the U.S. legal space is primarily to gather information related to U.S. national security and international trade,” the warning said.

UNC5221 collects technical information to identify software vulnerabilities, enabling long-term access and lateral movement across networks. Google’s Doug Bienstock emphasized the scale of the threat, noting that while the average global dwell time for intrusions is 10 days, UNC5221 typically remains undetected for over a year—averaging 393 days.

The group is suspected of links to China but has not been officially equated with other well-known China-based actors. In March, Microsoft identified “Silk Typhoon” as a Chinese espionage group exploiting remote management tools, though Mandiant says it treats UNC5221 separately.

Law firms are particularly vulnerable because of their role in patent disputes, insurance matters, mergers, and acquisitions. According to Storm Guidance CEO Neil Hare-Brown, “Their goal is the theft of intellectual property, and they target law firms by first compromising their technology suppliers.”

The legal industry is not the only target. SaaS providers, business process outsourcers, and technology companies have also been hit since March 2025. Mandiant reports that some attacks focused on developer and system administrator emails, while others targeted individuals tied to economic and geopolitical matters of interest to Beijing.

Other groups also remain active against the sector. Silent Ransom, a separate cybercrime gang, has been linked to more than 50 law firm breaches, including Am Law 100 firm Fenwick & West. The convergence of espionage-driven campaigns and profit-motivated ransomware highlights a growing, multifaceted threat to legal services.

Customer Stories

See how leading enterprise in-house teams have scaled smarter with Legal.io's high-caliber flex talent.

More from Legal.io


All Aboard The Next LegalTech AI Hype Train, The GPT-3 Express!
All Aboard The Next LegalTech AI Hype Train, The GPT-3 Express!

Brad Newman, Associate Director of Practice Innovation Services at Cooley LLP writes an interesting take on GPT: "Unlike, say, the fever dreams caused by IBM's Watson (RIP ROSS Intelligence) or your lawyer's latest journey into the Metaverse, we may see real advancements in intellectual efficiency from legal applications powered by GPT tools, in particular those built on Open AI's GPT-3 series."

Dec 08, 2022
Read More
Community Perspectives: Do your years of experience "reset" when you go in-house?
Community Perspectives: Do your years of experience "reset" when you go in-house?

In-house legal professionals discuss how they perceive years of experience in a law firm vs. in-house, and how they correlate to each other.

Oct 27, 2022
Read More
Net Neutrality on the Brink: Court Decision Plunges Internet Freedom into Uncertainty
Net Neutrality on the Brink: Court Decision Plunges Internet Freedom into Uncertainty

A U.S. appeals court has temporarily halted the FCC's reinstatement of net neutrality rules until August 5, 2024, following a challenge from ISPs and trade groups.

Jul 15, 2024
Read More
Meta Appoints C.J. Mahoney As Chief Legal Officer Amid Big Tech Legal Reshuffle

Meta has hired former Microsoft executive C.J. Mahoney as chief legal officer, as senior legal leadership continues to shift across the technology sector.

Jan 08, 2026
Read More
Ready to hire?

Schedule a free consultation to discuss your hiring needs.

Free 15-min consultation
Legal.io Platform
5 star reviews
Hiring made smarter

Easy-to-use platform for hiring legal talent, managing spend, and optimizing your panel — plus an average savings of 50%.

Need Immediate Help?

Submit a hiring request and let our experts handle the entire process for you.