INTEL_REPORT
Microsoft Security Blog · published 5/22/2026, 4:53:39 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerberos relay and lateral movement, and how Microsoft Defender detected, blocked, and unraveled the attack. The post From edge appliance to enterprise compromise: Multi-…
https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence
sha256:310810c55447b312698b81d1c5a7b8bfbcbf25b9757bc74c0335104bebe1d495
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| confluence.cfg.xml |
| Open → |
| domain | cve-2025-33073.py | Open → |
| domain | dnstool.py | Open → |
| domain | ip.ipaddress | Open → |
| domain | left.remoteip | Open → |
| domain | right.sourceipaddress | Open → |
| domain | bootstrap.jar | Open → |
| domain | setenv.sh | Open → |
| domain | my.f5.com | Open → |
| domain | thehackernews.com | Open → |
| domain | cisa-adds-cve-2025-53521-to-kev-after.html | Open → |
| domain | www.zscaler.com | Open → |
| domain | www.darktrace.com | Open → |
| url | http://206.189.27.39:8888/5 | Open → |
| url | https://my.f5.com/manage/s/article/K000156741 | Open → |
| url | https://thehackernews.com/2026/03/cisa-adds-cve-2025-53521-to-kev-after.html | Open → |
| url | https://www.zscaler.com/blogs/security-research/cisco-firewall-and-vpn-zero-day-attacks-cve-2025-20333-and-cve-2025-20362 | Open → |
| url | https://www.darktrace.com/blog/darktraces-view-on-operation-lunar-peek-exploitation-of-palo-alto-firewall-devices-cve-2024-2012-and-2024-9474 | Open → |
| sha256 | 4a927d031919fd6bd88d3c8a917214b54bca00f8ddc80ecfe4d230663dda7465 | Open → |
| sha256 | b4592cea69699b2c0737d4e19cff7dca17b5baf5a238cd6da950a37e9986f216 | Open → |
| sha256 | 710a9d2653c8bd3689e451778dab9daec0de4c4c75f900788ccf23ef254b122a | Open → |
| sha256 | 57b3188e24782c27fdf72493ce599537efd3187d03b80f8afe733c72d68c5517 | Open → |
| sha256 | bdd5da81ac34d9faa2a5118d4ed8f492239734be02146cd24a0e34270a48a455 | Open → |
| cve | CVE-2024-2012 | Open → |