Actor Profile
The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments. The actor demonstrated knowledge of edge appliance vulnerabilities and internal enterprise infrastructure, suggesting moderate sophistication and familiarity with common corporate technology stacks including F5 BIG-IP and Atlassian Confluence deployments.
TTPs (Tactics, Techniques, Procedures)
Initial access was achieved via exploitation of an exposed F5 BIG-IP edge appliance (T1190: Exploit Public-Facing Application). The actor then performed lateral movement (T1021) to an internal Confluence server, where credential theft (T1003: OS Credential Dumping, T1555: Credentials from Password Stores) and identity compromise occurred. Kerberos relay techniques (T1558: Steal or Forge Kerberos Tickets) were attempted for privilege escalation and further lateral movement within the Active Directory environment.
Targets & Patterns
The campaign targeted enterprise and technology sector organizations with exposed F5 BIG-IP appliances. The focus on Confluence servers suggests targeting of organizations using Atlassian collaboration platforms, which are prevalent in technology companies and large enterprises. The use of Kerberos relay indicates the actor sought to compromise Windows Active Directory environments for persistent access and privilege escalation. The targeting pattern suggests opportunistic exploitation of internet-facing assets followed by methodical internal reconnaissance.
Historical Context
This attack follows established patterns of exploiting edge infrastructure devices for initial access, a trend observed across multiple threat actor groups since 2020. F5 BIG-IP appliances have been targeted in previous campaigns exploiting CVEs such as CVE-2020-5902 and CVE-2022-1388. The pivot to Confluence aligns with increased targeting of collaboration platforms observed throughout 2022-2024, as organizations expanded remote work infrastructure. The specific combination of F5 and Confluence exploitation has not been widely documented in prior public reporting.
Defensive Recommendations
- Monitor F5 BIG-IP appliances for unauthorized access attempts and ensure all CVEs are patched; enable logging for T1190 exploitation attempts via web application firewall rules
- Implement network segmentation to restrict lateral movement from edge appliances to internal collaboration servers like Confluence (T1021)
- Deploy detection rules for Kerberos ticket anomalies including T1558.003 (Kerberoasting) and T1558.001 (Golden Ticket) via Windows Event IDs 4768, 4769, and 4770
- Enable credential guard and monitor for T1003 credential dumping attempts on Confluence servers using EDR telemetry and process execution monitoring
- Harden Confluence instances by disabling unnecessary services, enforcing MFA, and monitoring for suspicious authentication patterns and credential access (T1555)
