Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
perimeter-device-exposureend-of-life-softwareinitial-access-methodlateral-movement-method

F5 BIG-IP Breach Led to Linux Pivot, Confluence RCE, and AD Relay Attempts

Updated 29d agoFirst seen May 22, 20265 sources

Microsoft reported a multi-stage intrusion that began with the compromise of an internet-facing F5 BIG-IP appliance and expanded into broader enterprise access. The attacker used the edge device to obtain SSH access to an internal Linux host, then carried out reconnaissance with tools including Nmap, gowitness, and other open-source utilities. Microsoft said the actor also downloaded a custom scanner, detected as HackTool:Linux/MalPack.B, from 206.189.27[.]39, and used the Linux foothold to identify an unpatched internal Atlassian Confluence server.

The attacker exploited Confluence for remote code execution, shifted payload staging to an FTP server on the initial Linux host after other delivery methods were blocked, and extracted credentials from Confluence configuration files. Those credentials were then used in attempts to move into Windows identity infrastructure through relay-style attacks against Active Directory, including Kerberos relay activity and exploitation of CVE-2025-33073, while the actor also tested SSL/TLS exposure with testssl. Microsoft said the case shows how end-of-life edge appliances, unpatched internal applications, and weak identity protections can combine into a single attack chain spanning network appliances, Linux systems, enterprise applications, and domain services.

Share:
F5 BIG-IP Breach Led to Linux Pivot, Confluence RCE, and AD Relay Attempts
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
May 22, 20261mo ago

Microsoft publishes analysis and hardening recommendations

On May 22, 2026, Microsoft published its analysis of the multi-stage Linux intrusion and warned that end-of-life edge appliances, unpatched internal applications, and weak identity protections can combine into enterprise compromise. It recommended treating internet-facing edge devices as Tier-0 assets, urgently patching internal web applications such as Confluence, hardening against NTLM/Kerberos relay, and enabling Defender protections on Linux servers.

SSL/TLS weaknesses probed with testssl during later-stage activity

Microsoft observed the actor using testssl to probe SSL/TLS weaknesses as part of the intrusion. This indicates additional assessment of internal services while the compromise was underway.

Actor attempts AD relay attacks and exploits CVE-2025-33073

Using the stolen credentials, the threat actor attempted relay-style authentication attacks against Active Directory, including Kerberos relay activity and exploitation of CVE-2025-33073. The activity showed a shift from system compromise toward identity-focused domain attacks.

Credentials stolen from Confluence configuration files

Following access to Confluence, the actor extracted credentials from Confluence configuration files. Those credentials were then used to support further movement toward identity infrastructure.

Payloads staged through FTP after delivery attempts were blocked

Microsoft said the actor used an FTP server on the initially compromised Linux host to stage payload delivery after other delivery methods were blocked. This reflects an adaptation in tooling and delivery to maintain progress in the intrusion.

Unpatched internal Confluence server identified and exploited

The attacker discovered an unpatched internal Atlassian Confluence server and exploited it for remote code execution. This gave the actor another internal execution point and expanded the compromise.

Internal reconnaissance conducted from compromised Linux host

From the internal Linux host, the actor performed broad reconnaissance using tools including Nmap and gowitness to map systems and identify additional targets. Microsoft also observed the download of a custom scanner detected as HackTool:Linux/MalPack.B from 206.189.27[.]39.

Actor uses F5 foothold to access internal Linux host via SSH

After compromising the edge appliance, the actor leveraged it to obtain SSH access to an internal Linux system and pivot from the perimeter into the internal environment. This marked the transition from edge-device compromise to internal network access.

Threat actor compromises internet-facing F5 BIG-IP appliance

Microsoft reported that a threat actor initially gained access through an internet-facing F5 BIG-IP edge appliance, establishing the foothold that began the intrusion chain. The blog does not specify when the compromise occurred.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

23 LINKEDOpen in app
Affected products
6 linked
Active DirectoryMicrosoft Defender For EndpointCopilot StudioBig-Ip Virtual EditionConfluenceMicrosoft 365 Copilot
Organizations
8 linked
AtlassianF5Microsoft CorporationGoogleCisco SystemsZscalerPalo Alto NetworksDarktrace
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.