logo

Hackers use F5 BIG-IP malware to stealthily steal data for years

ID: a195b071-91a2-536e-835f-ccc49d2c97a7

STIX ID: report--a195b071-91a2-536e-835f-ccc49d2c97a7

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-06-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Sygnia observed a suspected Chinese APT, 'Velvet Ant', compromise exposed legacy F5 BIG-IP appliances via known RCE vulnerabilities to install custom implants (PMCD, MCDP, SAMRID, ESRDE) and use those devices to deploy PlugX to internal servers, maintain long-term persistence, and exfiltrate sensitive customer and financial data for roughly three years; recommended mitigations include patching, removing internet-exposed management interfaces, network segmentation, outbound connection restrictions, and replacing legacy devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.