F5 disclosed that a state-sponsored intruder maintained long-term access to its environment and stole sensitive data including BIG-IP source code, details of reported but not yet patched or disclosed vulnerabilities, and configuration and implementation information for a limited number of customers. Reporting attributed the intrusion to the China-linked group UNC5221, which allegedly used the BRICKSTORM backdoor and remained in the environment for more than 12 months. F5 said the incident did not involve a supply-chain compromise and did not affect CRM, financial systems, customer support, iHealth, or systems tied to other product lines.
Mandiant separately published hunting guidance describing BRICKSTORM as a stealthy espionage backdoor deployed on edge devices and appliances, with operators pivoting into enterprise environments through suspicious outbound traffic, appliance management interfaces, Windows Type 3 logons, occasional RDP, Microsoft 365 mail access abuse, and VMware vCenter or ESXi account manipulation. Defenders were urged to scan appliance files and backups with YARA and a Linux/BSD appliance scanner, review logs for rare DNS-over-HTTPS activity, inspect Windows User Access Logs, and check vCenter audit trails for temporary local accounts used to install BRICKSTORM. F5 said it rotated cryptographic material and released updates for BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, and APM clients to address 44 vulnerabilities, including the leaked issues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In response to the intrusion, F5 said it worked with Mandiant, CrowdStrike, NCC Group, and IOActive, rotated cryptographic material, and released security updates. The updates covered BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, and APM clients and addressed 44 vulnerabilities, including leaked ones.
Bloomberg attributed the F5 intrusion to the China-linked group UNC5221 using BrickStorm malware, with reported dwell time of more than 12 months. The attribution connected the F5 breach to the broader BRICKSTORM espionage activity.
F5 confirmed it was the victim of a cyberattack in which a state-sponsored group had long-term access to its systems and exfiltrated sensitive data, including BIG-IP source code, information on unpatched or undisclosed vulnerabilities, and limited customer configuration details. F5 said there was no supply-chain compromise and that CRM, financial, customer support, iHealth, and other product-line systems were not affected.
Mandiant published detection and hunting guidance for the BRICKSTORM backdoor, including YARA-based file and backup scanning and a scanner script for Linux/BSD-based appliances. The guidance also described actor tradecraft such as pivoting from appliances into Windows systems, suspicious Microsoft 365 mailbox access, and creation and deletion of local vCenter or ESXi accounts to install BRICKSTORM.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.