Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachstate-sponsored-espionagebreach-disclosure-notificationvendor-distribution-compromise

F5 Breach Involving Advanced Brickstorm Malware and Supply Chain Risks

Updated 3mo agoFirst seen Dec 5, 20252 sources

F5, a major application delivery and security provider, disclosed a significant breach in which malicious actors maintained persistent access to critical systems, including the BIG-IP product development environment and engineering knowledge management platform. The breach, which began in August and was deemed material by September, prompted F5 to delay public notification due to national security concerns. Upon disclosure, F5 released security patches for affected products, and CISA issued an emergency directive requiring federal agencies to patch vulnerable F5 devices immediately. The advanced 'Brickstorm' malware, attributed to Chinese threat actors, was detected as part of this breach, raising concerns about the potential for long-term exploitation of stolen technical specifications and code.

While there is currently no evidence that the stolen information has been used to exploit F5 devices or alter the codebase, the incident highlights the ongoing risks associated with software supply chain attacks. The breach underscores the challenges organizations face in securing complex supply chains, as even widely adopted security frameworks may not fully mitigate such threats. The F5 incident draws parallels to previous high-profile supply chain compromises, emphasizing the need for more robust and comprehensive security measures to protect critical infrastructure and sensitive data from sophisticated nation-state actors.

Share:
F5 Breach Involving Advanced Brickstorm Malware and Supply Chain Risks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 4, 20257mo ago

Malware infection linked to the F5 breach is detected

A malware infection was detected in connection with the recently disclosed F5 breach, drawing attention from CISA and the NSA. U.S. officials assessed the incident as serious, though public details on the malware and scope of compromise remained limited.

Oct 1, 20259mo ago

CISA issues emergency directive to patch affected F5 products

Following F5's disclosure, CISA directed federal agencies to patch affected F5 products on an emergency basis. The action reflected concern that stolen technical data could enable follow-on attacks against government systems.

F5 discloses a material breach of internal systems

In October, F5 disclosed that it had suffered a long-term breach affecting internal systems and its BIG-IP development environment. The company said the incident was material and potentially posed national security implications, though no evidence of code tampering or active exploitation had been identified.

Aug 1, 202511mo ago

Unauthorized access begins in F5 internal systems

F5 later determined that attackers had unauthorized access to its internal systems, including the BIG-IP product development environment, beginning in August. The intrusion was described as long-term and raised concerns about software supply chain risk.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Threat actors
1 linked
Organizations
5 linked
F5CISANational Security AgencySolarWindsMicrosoft Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.