← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
A sophisticated multi-stage intrusion began with the compromise of an internet-facing F5 BIG-IP load balancer running an end-of-life version. The threat actor established SSH access to a Linux server using privileged credentials, then conducted extensive reconnaissance including network scanning with Nmap and service enumeration with gowitness. Following horizontal and vertical scanning operations, the actor identified and compromised an unpatched internal Atlassian Confluence server via remote code execution. Credentials extracted from Confluence configuration files were subsequently used to attempt Kerberos relay attacks against Active Directory infrastructure and exploit CVE-2025-33073. The incident demonstrates how edge device compromises enable lateral movement across hybrid environments, bypassing traditional security controls through trusted relationships and exploiting insufficient monitoring of non-Windows systems and internal applications.
MITRE ATT&CK & Malware Families
Indicators of Compromise (5 / 10 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 4a927d031919fd6bd88d3c8a917214b54bca00f8ddc80ecfe4d230663dda7465 | — | 2026-05-22 | |
| FileHash-SHA256 | 57b3188e24782c27fdf72493ce599537efd3187d03b80f8afe733c72d68c5517 | — | 2026-05-22 | |
| FileHash-SHA256 | 710a9d2653c8bd3689e451778dab9daec0de4c4c75f900788ccf23ef254b122a | — | 2026-05-22 | |
| FileHash-SHA256 | b4592cea69699b2c0737d4e19cff7dca17b5baf5a238cd6da950a37e9986f216 | — | 2026-05-22 | |
| FileHash-SHA256 | bdd5da81ac34d9faa2a5118d4ed8f492239734be02146cd24a0e34270a48a455 | — | 2026-05-22 |