Microsoft reported a multi-stage intrusion that began with the compromise of an internet-facing F5 BIG-IP appliance and expanded into broader enterprise access. The attacker used the edge device to obtain SSH access to an internal Linux host, then carried out reconnaissance with tools including Nmap, gowitness, and other open-source utilities. Microsoft said the actor also downloaded a custom scanner, detected as HackTool:Linux/MalPack.B, from 206.189.27[.]39, and used the Linux foothold to identify an unpatched internal Atlassian Confluence server.
The attacker exploited Confluence for remote code execution, shifted payload staging to an FTP server on the initial Linux host after other delivery methods were blocked, and extracted credentials from Confluence configuration files. Those credentials were then used in attempts to move into Windows identity infrastructure through relay-style attacks against Active Directory, including Kerberos relay activity and exploitation of CVE-2025-33073, while the actor also tested SSL/TLS exposure with testssl. Microsoft said the case shows how end-of-life edge appliances, unpatched internal applications, and weak identity protections can combine into a single attack chain spanning network appliances, Linux systems, enterprise applications, and domain services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On May 22, 2026, Microsoft published its analysis of the multi-stage Linux intrusion and warned that end-of-life edge appliances, unpatched internal applications, and weak identity protections can combine into enterprise compromise. It recommended treating internet-facing edge devices as Tier-0 assets, urgently patching internal web applications such as Confluence, hardening against NTLM/Kerberos relay, and enabling Defender protections on Linux servers.
Microsoft observed the actor using testssl to probe SSL/TLS weaknesses as part of the intrusion. This indicates additional assessment of internal services while the compromise was underway.
Using the stolen credentials, the threat actor attempted relay-style authentication attacks against Active Directory, including Kerberos relay activity and exploitation of CVE-2025-33073. The activity showed a shift from system compromise toward identity-focused domain attacks.
Following access to Confluence, the actor extracted credentials from Confluence configuration files. Those credentials were then used to support further movement toward identity infrastructure.
Microsoft said the actor used an FTP server on the initially compromised Linux host to stage payload delivery after other delivery methods were blocked. This reflects an adaptation in tooling and delivery to maintain progress in the intrusion.
The attacker discovered an unpatched internal Atlassian Confluence server and exploited it for remote code execution. This gave the actor another internal execution point and expanded the compromise.
From the internal Linux host, the actor performed broad reconnaissance using tools including Nmap and gowitness to map systems and identify additional targets. Microsoft also observed the download of a custom scanner detected as HackTool:Linux/MalPack.B from 206.189.27[.]39.
After compromising the edge appliance, the actor leveraged it to obtain SSH access to an internal Linux system and pivot from the perimeter into the internal environment. This marked the transition from edge-device compromise to internal network access.
Microsoft reported that a threat actor initially gained access through an internet-facing F5 BIG-IP edge appliance, establishing the foothold that began the intrusion chain. The blog does not specify when the compromise occurred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.