Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2026-02-24abuse.chabuse.ch
MalwareBazaar | SHA256 63deffbdd4053a38c95221589cc2ddd0595d451808a79432fa9f5476c4542390 (WalkLoader)
WalkLoader
2025-10-21AnomaliAnomali Cyber Watch
Anomali Cyber Watch: F5 Breach, Mysterious Elephant APT, Malicious MCP Servers, and More
MonsterV2 Mysterious Elephant
2025-10-16QualysDiksha Ojha
F5 BIG-IP Source Code Leaked in State-Linked Cyberattack (BRICKSTORM Malware)
BRICKSTORM
2025-06-10abuse.ch
MalwareBazaar | SHA256 73fd51d4a0959e5c5a82db9be0d765069d02a2b97f51f55f5d6422a7bec01caa (AmateraStealer)
Amatera
2024-06-03SYGNIASygnia Team
China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence
PlugX
2024-03-22RH-ISACLee Clark
Chinese Threat Group UNC5174 Reportedly Exploiting F5 BIG-IP and ScreenConnect CVEs for Active Exploitation
GOREVERSE SNOWLIGHT Sliver UNC5174
2024-03-21MandiantAdam Aprahamian, Austin Larsen, Dan Kelly, Marcin Siedlarz, Mathew Potaczek, Michael Raggi
Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect
GOREVERSE SNOWLIGHT Sliver UNC5174
2024-03-21MandiantAdam Aprahamian, Austin Larsen, Dan Kelly, Marcin Siedlarz, Mathew Potaczek, Michael Raggi
Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect
GOREVERSE SNOWLIGHT
2023-10-03ElasticAndrew Pease, Cyril François, Daniel Stepanic, Salim Bitam, Seth Goodwin
Introducing the REF5961 intrusion set (RUDEBIRD, DOWNTOWN, and EAGERBEE)
EagerBee SManager REF2924 REF5961
2022-09-15JPCERT/CCShusei Tomonaga
F5 BIG-IP Vulnerability (CVE-2022-1388) Exploited by BlackTech
Hipid
2022-08-15F5 LabsAditya K. Sood, David Warburton, Malcolm Heath, Sander Vinberg
BlackGuard Infostealer Malware: Dissecting the State of Exfiltrated Data
BlackGuard
2022-06-15F5 LabsDavid Warburton, Dor Nizar, Malcolm Heath, Sander Vinberg
F5 Labs Investigates MaliBot
2022-05-12Lacework LabsChris Hall, Jared Stroud
Malware targeting latest F5 vulnerability
Mirai
2022-04-23F5Aditya K. Sood
Cryptojacking on the Fly: TeamTNT Using NVIDIA Drivers to Mine Cryptocurrency
2022-02-02lodestoneGroup-IB, Jason Daza, Manoj Khatiwada, Michael Wirtz, Paul Brunney
White Rabbit Continued: Sardonic and F5
2022-01-13F5Dor Nizar, Roy Moshailov
FluBot’s Authors Employ Creative and Sophisticated Techniques to Achieve Their Goals in Version 5.0 and Beyond
FluBot
2021-12-08F5Aditya K. Sood, Rohit Chaturvedi
Collector-stealer: a Russian origin credential and information extractor
2021-04-07F5Aditya K. Sood
Dissecting the Design and Vulnerabilities in Azorult C&C Panels
Azorult
2021-03-04F5Dor Nizar, Roy Moshailov
IcedID Banking Trojan Uses COVID-19 Pandemic to Lure New Victims
IcedID
2021-01-01lodestoneLodestone
White Rabbit Ransomware and the F5 Backdoor