ATT&CKReferencesResecurity UNC5221 BRICKSTORM F5 Big-IP October 2025

Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025

Resecurity Threat Intelligence & Incident Analysis. (2025, October 22). F5 BIG-IP Source Code Leak Tied to State-Linked Campaigns Using BRICKSTORM Backdoor. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareBRICKSTORM

BRICKSTORM has uploaded files from the victim system to C2 servers.

T1132.001
Standard Encoding
MalwareBRICKSTORM

BRICKSTORM has leveraged Base64 to encode C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareBRICKSTORM

BRICKSTORM has decoded its encrypted C2 traffic prior to execution. BRICKSTORM also has the ability to decode its obfuscated payload before execution.

T1572
Protocol Tunneling
MalwareBRICKSTORM

BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket.

T1573.002
Asymmetric Cryptography
MalwareBRICKSTORM

BRICKSTORM has communicated with C2 infrastructure via TLS.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.