DFIR Tech Blog – an AI playground

Deutsch English
Foto von Jordan Harrison auf Unsplash.com

F5 BIG-IP: Forensics After the Source Code Theft

04.08.2026 supply-chainedge-devicesnation-statethreat-hunting

A Year in the Dark

On October 15, 2025, F5 Networks disclosed something that alarmed security teams worldwide. “In August 2025, we learned a highly sophisticated nation-state threat actor maintained long-term, persistent access to, and downloaded files from, certain F5 systems,” the company stated. The number that really made people sit up came shortly after, via Bloomberg reporting: the attackers were in the company’s network for at least 12 months, and the intrusion involved a malware family dubbed BRICKSTORM, attributed to a China-nexus cyber espionage group tracked as UNC5221.

For forensic investigators, this case is instructive on several levels. First, it shows a vendor becoming the primary target itself—not to steal customer data, but to obtain the “blueprints” of its own products. What was compromised included engineering knowledge management systems, source repositories, and internal configuration files for a limited subset of customer deployments. Analysis makes clear this was not a smash-and-grab operation—the attackers had time to explore these sensitive environments methodically.

Why BRICKSTORM Defeats Classic Forensics

The real reason this case matters lies in the tooling used. BRICKSTORM is no ordinary malware; it is a Go-based backdoor fitted with capabilities to set itself up as a web server, perform file system and directory manipulation, upload/download files, execute shell commands, and act as a SOCKS relay, communicating with a C2 server via WebSockets. Crucially for responders, these intrusions are conducted with a particular focus on maintaining long-term stealthy access by deploying backdoors on appliances that do not support traditional EDR tools.

That’s exactly what makes network appliances like BIG-IP such attractive targets: there’s no host agent generating forensic telemetry. Mandiant/GTIG analysts further observed that the backdoor showed extremely long dwell times in the hundreds of days, persistence via modified startup scripts and cloned VMs, and downstream compromise through service providers. In at least one documented case, the group’s persistence became strikingly clear: attackers even installed BRICKSTORM on a vCenter server after incident response had already begun.

For forensic practice, this means host-based evidence collection alone is no longer sufficient. Network forensics—such as analyzing DNS-over-HTTPS resolutions, which according to a December 19, 2025 CISA update are frequently used to resolve C2 infrastructure—is becoming essential. CISA has since released updated YARA and Sigma rules specifically designed to detect BRICKSTORM, a clear signal that signature-based detection alone is no longer enough.

Threat Hunting, Not Just Patch Compliance

For organizations running BIG-IP environments, the focus is shifting away from pure patch compliance toward active threat hunting. F5 itself provided guidance: a threat hunting guide to strengthen detection and monitoring is available from F5 support. Practical hunting playbooks recommend focusing on multiple layers simultaneously: management and API access (iControl REST), abnormal configuration/archive downloads, webshells or command execution on BIG-IP, and suspicious outbound file transfer/exfiltration behavior.

Concretely, this means correlating logs across sources—BIG-IP/F5 logs (/var/log/ltm, /var/log/audit), HTTP access logs, system/EDR process execution logs, and network/proxy/Zeek data on outbound connections. Particularly sensitive: access to backup and configuration files with extensions like .ucs, .tar, .zip, or .conf, since these formats are commonly abused for exfiltration.

The regulatory response underscores the severity: CISA issued Emergency Directive 26-01, and required federal agencies to patch affected systems immediately—reflecting the criticality of this supply-chain compromise. Yet the deeper risk remains latent: stolen source code and undisclosed vulnerability data could resurface months or years later as precisely crafted zero-day exploits—a threat that breaks the classic incident response cycle and forces organizations into sustained, proactive monitoring of their edge infrastructure.

← Back to overview