Hackers target F5 products with dangerous malware

representational image of a cloud firewall
Image Credit: Pixabay (Image credit: Pixabay)

A hacking collective was stealing sensitive information from a company, using vulnerable F5 BIG-IP appliances to break in and achieve persistence.

A report from cybersecurity researchers Sygnia outlined how the group, which is suspected to be of Chinese origin, found multiple F5 BIG-IP endpoints running vulnerable OS versions.

They used the known vulnerabilities to deploy PlugX, a modular remote access Trojan (RAT) which is, apparently, the go-to solution for many Chinese threat actors. PlugX, available on the black market for roughly a decade now, is usually used to harvest, and exfiltrate, information from compromised endpoints.

Velvet Ant

Besides PlugX, the group used a whole slew of other malware, including PMCD (used for maintaining remote control), MCDP (ensures persistent network monitoring), SAMRID (AKA EarthWorm, a SOCKS proxy tunneler), and ESRDE, used for remote command control and persistence. Sygnia reports that despite extensive eradication efforts following the breach's discovery, the hackers re-deployed PlugX with new configurations to avoid detection, using compromised internal devices like the F5 appliances to retain access.

While Sygnia did not name the vulnerable organization (which is allegedly based in east Asia), it did say that removing malware from F5 BIG-IP instances was a challenge, and that the group redeployed PlugX as soon as the devices were cleaned. 

That being said, the researchers now recommend vulnerable organizations take multiple steps, including restricting outbound connections, implementing strict controls over management ports, deploying robust EDR systems, enhancing security for edge devices, and ultimately - replacing legacy systems. After all, the targeted devices were running vulnerable versions of the operating system, and the attacks could have been avoided by simply keeping the devices updated. 

The group is dubbed Velvet Ant.

Via BleepingComputer

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
China
Chinese hackers develop effective new hacking technique to go after business networks
A computer being guarded by cybersecurity.
Huge cyberattack found hitting vulnerable Microsoft-signed legacy drivers to get past security
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
A major FBI operation has deleted Chinese malware from thousands of US computers
Mustang Panda
Chinese hackers abuse Microsoft tool to get past antivirus and cause havoc
Cyber-security
Top file-sharing tools are being hit by security attacks once again
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day