CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via apmd Process — Active Exploitation by UNC5221 (BRICKSTORM)

CVE-2025-53521 (TL-2026-0297), also tracked as BRICKSTORM Campaign, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-03-30. It is attributed to UNC5221 (China) with high confidence, affects F5 BIG-IP Access Policy Manager (APM), references 1 CVE (CVE-2025-53521), maps to 24 MITRE ATT&CK techniques (T1016, T1021, T1027), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-0297

Threat ID
TL-2026-0297
Also known as
BRICKSTORM Campaign, F5 BIG-IP APM RCE
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-03-30
Last reviewed
2026-03-30
Attribution
UNC5221
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government, information-technology, financial, legal, healthcare, defense, critical-infrastructure, telecommunications
Target regions
North America, Europe, United Kingdom, Netherlands, Asia-Pacific
Detection rules
9
Indicators of compromise
27

Malware and tooling in CVE-2025-53521

Malware and tooling: BRICKSTORM - S9015, BRICKSTORM C2 via DoH + WebSocket + Yamux multiplexing

Critical unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM) apmd process (CVE-2025-53521, CVSS 9.8). Originally disclosed as DoS in October 2025, reclassified as RCE in March 2026 after discovery of active exploitation by China-nexus threat actor UNC5221, who had breached F5 networks for 12+ months and deployed the BRICKSTORM backdoor on customer systems. CISA KEV listed March 27, 2026 with remediation deadline March 30, 2026.

How CVE-2025-53521 works

CVE-2025-53521 is a critical unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM) affecting the apmd process, which handles live traffic processing. The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) and allows remote attackers to achieve code execution by sending specially crafted traffic to a virtual server with a BIG-IP APM access policy configured.

The vulnerability was initially published on October 15, 2025 as a denial-of-service issue, but was reclassified as an RCE in March 2026 after F5 obtained new information confirming the true severity. The CVSS score was upgraded from 8.7 to 9.8 (v3.1) and 9.3 (v4.0).

The exploitation is attributed to UNC5221 (also tracked as UTA0178 and Red Dev 61), a China-nexus state-sponsored threat cluster. F5 confirmed on October 16, 2025 that a highly sophisticated nation-state threat actor had maintained access to F5 internal networks for at least 12 months (discovered August 9, 2025). During this intrusion, attackers exfiltrated BIG-IP source code, internal development data, and intelligence about undisclosed vulnerabilities.

Post-compromise, UNC5221 deployed the BRICKSTORM backdoor — a Golang-based, cross-platform implant targeting Linux, Windows, and BSD systems — on F5 customer environments. BRICKSTORM communicates via TLS with HTTP/2 ALPN negotiation, WebSocket upgrades for persistent bidirectional tunnels, and Yamux multiplexing. It uses DNS-over-HTTPS (DoH) for C2 resolution via Cloudflare, Google, and Quad9 resolvers, and leverages cloud services (Cloudflare Workers, Heroku) as reverse proxies to mask traffic.

Observed post-exploitation techniques include: deployment of PHP webshells to /var/sam/www/webtop/renderer/ paths (apm_css.php3, full_wt.php3, webtop_popup_css.php3), though many webshells operate in-memory only; modification of /usr/bin/umount and /usr/sbin/httpd binaries to subvert the sys-eicheck integrity checker; disabling SELinux via iControl REST API from localhost; and reconnaissance via the /mgmt/shared/identified-devices/config/device-info endpoint. Attackers disguise outbound C2 traffic using HTTP 201 response codes with CSS content-type headers.

Attackers modified components only in the running partition, failing to replicate changes to the upgrade destination partition — meaning customers who had already upgraded and rebooted lost attacker modifications, effectively removing the compromise. This is a critical remediation detail.

CISA added CVE-2025-53521 to the Known Exploited Vulnerabilities catalog on March 27, 2026, with a federal remediation deadline of March 30, 2026. The Dutch NCSC has also confirmed observations of active abuse. Over 22 F5 BIG-IP modules are affected across four major version branches.

MITRE ATT&CK techniques used in TL-2026-0297

discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery

lateral-movement

T1021 Remote Services; T1210 Exploitation of Remote Services

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter; T1106 Native API

command-and-control

T1071 Application Layer Protocol; T1090 Proxy; T1572 Protocol Tunneling; T1573 Encrypted Channel

initial-access

T1190 Exploit Public-Facing Application

impact

T1489 Service Stop

persistence

T1505 Server Software Component; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

credential-access

T1556 Modify Authentication Process

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CVE-2025-53521

  • F5 — BIG-IP Access Policy Manager (APM)
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
  • F5 — BIG-IP Advanced Firewall Manager (AFM)
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
  • F5 — BIG-IP Application Security Manager (ASM)
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
  • F5 — BIG-IP Local Traffic Manager (LTM)
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
  • F5 — BIG-IP SSL Orchestrator
    Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
    Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8
  • F5 — F5OS-A / F5OS-C
    Vulnerable versions: Multiple versions
    Fixed in: See F5 advisory K000156741
  • F5 — BIG-IP Next SPK / CNF
    Vulnerable versions: Multiple versions
    Fixed in: See F5 advisory K000156741

Remediation for CVE-2025-53521

Patches

  • F5 BIG-IP 17.5.x: Upgrade to 17.5.1.3
  • F5 BIG-IP 17.1.x: Upgrade to 17.1.3
  • F5 BIG-IP 16.1.x: Upgrade to 16.1.6.1
  • F5 BIG-IP 15.1.x: Upgrade to 15.1.10.8

Immediate actions

  • Apply F5 patches immediately: upgrade to 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8
  • Check for IOCs: verify /usr/bin/umount and /usr/sbin/httpd hashes against known-good versions
  • Review /var/log/restjavad-audit logs for unauthorized localhost iControl REST API access
  • Check for presence of /run/bigtlog.pipe and /run/bigstart.ltm files
  • Inspect /var/sam/www/webtop/renderer/ for modified PHP3 files (apm_css.php3, full_wt.php3, webtop_popup_css.php3)
  • Isolate affected BIG-IP systems from the network pending investigation
  • Block outbound DoH traffic to 1.1.1.1, 8.8.8.8, 9.9.9.9 from BIG-IP management interfaces

Workarounds

  • Remove APM access policies from virtual servers if not required (eliminates attack surface)
  • Restrict management plane access to trusted networks only
  • Note: upgrading and rebooting removes attacker modifications from running partition

Longer-term hardening

  • Deploy network detection for BRICKSTORM C2 patterns (HTTP/2 + WebSocket + Yamux multiplexing)
  • Implement integrity monitoring on BIG-IP system binaries
  • Restrict iControl REST API access to authorized management stations only
  • Monitor for HTTP 201 responses with CSS content-type from BIG-IP systems
  • Conduct full threat hunt across all F5 BIG-IP infrastructure
  • Engage CISA-certified incident response provider for forensic investigation

CVEs associated with CVE-2025-53521

CVE-2025-53521

Weaknesses (CWE) in CVE-2025-53521

CWE-770

Timeline of CVE-2025-53521

  • Estimated start of UNC5221 intrusion into F5 internal networks (12+ months before discovery in August 2025)
  • F5 discovers unauthorized access to internal systems by sophisticated nation-state threat actor linked to China
  • Google Mandiant publishes BRICKSTORM espionage campaign analysis identifying UNC5221 targeting tech and legal sectors
  • F5 publishes security advisory K000156741 for CVE-2025-53521, initially classified as denial-of-service (CVSS 8.7)
  • F5 releases patches for 24 vulnerabilities across BIG-IP, F5OS-A, F5OS-C, and BIG-IP Next platforms
  • F5 publicly discloses breach by nation-state actor; confirms BIG-IP source code and vulnerability intelligence stolen (disclosure delayed under DOJ authorization)
  • CISA, NSA, and FBI release BRICKSTORM Malware Analysis Report (AR25-338A) with IOCs and detection signatures from 12 samples
  • CISA updates BRICKSTORM advisory with additional variant sample analysis and updated IOCs
  • CISA publishes analysis of new BRICKSTORM variant with different capabilities than previously documented samples
  • New information obtained confirming CVE-2025-53521 enables remote code execution, not just denial-of-service
  • CISA adds CVE-2025-53521 to Known Exploited Vulnerabilities catalog with federal remediation deadline March 30, 2026
  • F5 reclassifies CVE-2025-53521 from DoS to RCE; CVSS upgraded from 8.7 to 9.8 (v3.1) and 9.3 (v4.0); NVD entry updated
  • Multiple security vendors confirm active exploitation of CVE-2025-53521 with BRICKSTORM backdoor deployment on customer systems
  • CISA KEV remediation deadline for FCEB agencies; all federal civilian systems must have patches applied or mitigations in place
  • UK NCSC publishes advisory; Dutch National Cyber Security Center (NCSC-NL) confirms observations of active abuse in Netherlands
  • As of 2026-05-29, CVE-2025-53521 (F5 BIG-IP APM RCE, CVSS 9.8) remains live: it is in CISA KEV and under active exploitation, with 14,000+ instances still internet-exposed/unpatched per Shadowserver. China-nexus UNC5221 continues deploying BRICKSTORM undisrupted, no takedown, arrest, or successor reported.

Sources cited for CVE-2025-53521

Threats related to CVE-2025-53521

Detection coverage for TL-2026-0297

As of 2026-03-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0297 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats