PULSE NAME
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
WHITE AlienVault 2026-05-22 Modified: 2026-05-25
10
IOCs
LOW VOLUME
A sophisticated multi-stage intrusion began with the compromise of an internet-facing F5 BIG-IP load balancer running an end-of-life version. The threat actor established SSH access to a Linux server using privileged credentials, then conducted extensive reconnaissance including network scanning with Nmap and service enumeration with gowitness. Following horizontal and vertical scanning operations, the actor identified and compromised an unpatched internal Atlassian Confluence server via remote code execution. Credentials extracted from Confluence configuration files were subsequently used to attempt Kerberos relay attacks against Active Directory infrastructure and exploit CVE-2025-33073. The incident demonstrates how edge device compromises enable lateral movement across hybrid environments, bypassing traditional security controls through trusted relationships and exploiting insufficient monitoring of non-Windows systems and internal applications.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
HackTool:Linux/MalPack.B HackTool:Linux/Kerbrute
Indicators of Compromise (10)
All CVE FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2024-2012 2026-05-22
CVE CVE-2025-20333 2026-05-22
CVE CVE-2025-20362 2026-05-22
CVE CVE-2025-33073 2026-05-22
CVE CVE-2025-53521 2026-05-22
FileHash-SHA256 4a927d031919fd6bd88d3c8a917214b54bca00f8ddc80ecfe4d230663dda7465 2026-05-22
FileHash-SHA256 57b3188e24782c27fdf72493ce599537efd3187d03b80f8afe733c72d68c5517 2026-05-22
FileHash-SHA256 710a9d2653c8bd3689e451778dab9daec0de4c4c75f900788ccf23ef254b122a 2026-05-22
FileHash-SHA256 b4592cea69699b2c0737d4e19cff7dca17b5baf5a238cd6da950a37e9986f216 2026-05-22
FileHash-SHA256 bdd5da81ac34d9faa2a5118d4ed8f492239734be02146cd24a0e34270a48a455 2026-05-22