Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-02-24 ⋅ abuse.ch ⋅ abuse.ch
MalwareBazaar | SHA256 63deffbdd4053a38c95221589cc2ddd0595d451808a79432fa9f5476c4542390 (WalkLoader)
WalkLoader
2025-10-21 ⋅ Anomali ⋅ Anomali Cyber Watch
Anomali Cyber Watch: F5 Breach, Mysterious Elephant APT, Malicious MCP Servers, and More
MonsterV2 Mysterious Elephant
2025-10-16 ⋅ Qualys ⋅ Diksha Ojha
F5 BIG-IP Source Code Leaked in State-Linked Cyberattack (BRICKSTORM Malware)
BRICKSTORM
2025-06-10 ⋅ abuse.ch
MalwareBazaar | SHA256 73fd51d4a0959e5c5a82db9be0d765069d02a2b97f51f55f5d6422a7bec01caa (AmateraStealer)
Amatera
2024-06-03 ⋅ SYGNIA ⋅ Sygnia Team
China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence
PlugX
2024-03-22 ⋅ RH-ISAC ⋅ Lee Clark
Chinese Threat Group UNC5174 Reportedly Exploiting F5 BIG-IP and ScreenConnect CVEs for Active Exploitation
GOREVERSE SNOWLIGHT Sliver UNC5174
2024-03-21 ⋅ Mandiant ⋅ Adam Aprahamian, Austin Larsen, Dan Kelly, Marcin Siedlarz, Mathew Potaczek, Michael Raggi
Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect
GOREVERSE SNOWLIGHT Sliver UNC5174
2024-03-21 ⋅ Mandiant ⋅ Adam Aprahamian, Austin Larsen, Dan Kelly, Marcin Siedlarz, Mathew Potaczek, Michael Raggi
Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect
GOREVERSE SNOWLIGHT
2023-10-03 ⋅ Elastic ⋅ Andrew Pease, Cyril François, Daniel Stepanic, Salim Bitam, Seth Goodwin
Introducing the REF5961 intrusion set (RUDEBIRD, DOWNTOWN, and EAGERBEE)
EagerBee SManager REF2924 REF5961
2022-09-15 ⋅ JPCERT/CC ⋅ Shusei Tomonaga
F5 BIG-IP Vulnerability (CVE-2022-1388) Exploited by BlackTech
Hipid
2022-08-15 ⋅ F5 Labs ⋅ Aditya K. Sood, David Warburton, Malcolm Heath, Sander Vinberg
BlackGuard Infostealer Malware: Dissecting the State of Exfiltrated Data
BlackGuard
2022-06-15 ⋅ F5 Labs ⋅ David Warburton, Dor Nizar, Malcolm Heath, Sander Vinberg
F5 Labs Investigates MaliBot
2022-05-12 ⋅ Lacework Labs ⋅ Chris Hall, Jared Stroud
Malware targeting latest F5 vulnerability
Mirai
2022-04-23 ⋅ F5 ⋅ Aditya K. Sood
Cryptojacking on the Fly: TeamTNT Using NVIDIA Drivers to Mine Cryptocurrency
2022-02-02 ⋅ lodestone ⋅ Group-IB, Jason Daza, Manoj Khatiwada, Michael Wirtz, Paul Brunney
White Rabbit Continued: Sardonic and F5
2022-01-13 ⋅ F5 ⋅ Dor Nizar, Roy Moshailov
FluBot’s Authors Employ Creative and Sophisticated Techniques to Achieve Their Goals in Version 5.0 and Beyond
FluBot
2021-12-08 ⋅ F5 ⋅ Aditya K. Sood, Rohit Chaturvedi
Collector-stealer: a Russian origin credential and information extractor
2021-04-07 ⋅ F5 ⋅ Aditya K. Sood
Dissecting the Design and Vulnerabilities in Azorult C&C Panels
Azorult
2021-03-04 ⋅ F5 ⋅ Dor Nizar, Roy Moshailov
IcedID Banking Trojan Uses COVID-19 Pandemic to Lure New Victims
IcedID
2021-01-01 ⋅ lodestone ⋅ Lodestone
White Rabbit Ransomware and the F5 Backdoor