CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via apmd Process — Active Exploitation by UNC5221 (BRICKSTORM)
CVE-2025-53521 (TL-2026-0297), also tracked as BRICKSTORM Campaign, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-03-30. It is attributed to UNC5221 (China) with high confidence, affects F5 BIG-IP Access Policy Manager (APM), references 1 CVE (CVE-2025-53521), maps to 24 MITRE ATT&CK techniques (T1016, T1021, T1027), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-0297
- Threat ID
- TL-2026-0297
- Also known as
- BRICKSTORM Campaign, F5 BIG-IP APM RCE
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-03-30
- Last reviewed
- 2026-03-30
- Attribution
- UNC5221
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, information-technology, financial, legal, healthcare, defense, critical-infrastructure, telecommunications
- Target regions
- North America, Europe, United Kingdom, Netherlands, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in CVE-2025-53521
Malware and tooling: BRICKSTORM - S9015, BRICKSTORM C2 via DoH + WebSocket + Yamux multiplexing
Critical unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM) apmd process (CVE-2025-53521, CVSS 9.8). Originally disclosed as DoS in October 2025, reclassified as RCE in March 2026 after discovery of active exploitation by China-nexus threat actor UNC5221, who had breached F5 networks for 12+ months and deployed the BRICKSTORM backdoor on customer systems. CISA KEV listed March 27, 2026 with remediation deadline March 30, 2026.
How CVE-2025-53521 works
CVE-2025-53521 is a critical unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM) affecting the apmd process, which handles live traffic processing. The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) and allows remote attackers to achieve code execution by sending specially crafted traffic to a virtual server with a BIG-IP APM access policy configured.
The vulnerability was initially published on October 15, 2025 as a denial-of-service issue, but was reclassified as an RCE in March 2026 after F5 obtained new information confirming the true severity. The CVSS score was upgraded from 8.7 to 9.8 (v3.1) and 9.3 (v4.0).
The exploitation is attributed to UNC5221 (also tracked as UTA0178 and Red Dev 61), a China-nexus state-sponsored threat cluster. F5 confirmed on October 16, 2025 that a highly sophisticated nation-state threat actor had maintained access to F5 internal networks for at least 12 months (discovered August 9, 2025). During this intrusion, attackers exfiltrated BIG-IP source code, internal development data, and intelligence about undisclosed vulnerabilities.
Post-compromise, UNC5221 deployed the BRICKSTORM backdoor — a Golang-based, cross-platform implant targeting Linux, Windows, and BSD systems — on F5 customer environments. BRICKSTORM communicates via TLS with HTTP/2 ALPN negotiation, WebSocket upgrades for persistent bidirectional tunnels, and Yamux multiplexing. It uses DNS-over-HTTPS (DoH) for C2 resolution via Cloudflare, Google, and Quad9 resolvers, and leverages cloud services (Cloudflare Workers, Heroku) as reverse proxies to mask traffic.
Observed post-exploitation techniques include: deployment of PHP webshells to /var/sam/www/webtop/renderer/ paths (apm_css.php3, full_wt.php3, webtop_popup_css.php3), though many webshells operate in-memory only; modification of /usr/bin/umount and /usr/sbin/httpd binaries to subvert the sys-eicheck integrity checker; disabling SELinux via iControl REST API from localhost; and reconnaissance via the /mgmt/shared/identified-devices/config/device-info endpoint. Attackers disguise outbound C2 traffic using HTTP 201 response codes with CSS content-type headers.
Attackers modified components only in the running partition, failing to replicate changes to the upgrade destination partition — meaning customers who had already upgraded and rebooted lost attacker modifications, effectively removing the compromise. This is a critical remediation detail.
CISA added CVE-2025-53521 to the Known Exploited Vulnerabilities catalog on March 27, 2026, with a federal remediation deadline of March 30, 2026. The Dutch NCSC has also confirmed observations of active abuse. Over 22 F5 BIG-IP modules are affected across four major version branches.
MITRE ATT&CK techniques used in TL-2026-0297
discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery
lateral-movement
T1021 Remote Services; T1210 Exploitation of Remote Services
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059 Command and Scripting Interpreter; T1106 Native API
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1572 Protocol Tunneling; T1573 Encrypted Channel
initial-access
T1190 Exploit Public-Facing Application
impact
persistence
T1505 Server Software Component; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
credential-access
T1556 Modify Authentication Process
resource-development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
defense-impairment
Affected products and versions in CVE-2025-53521
- F5 — BIG-IP Access Policy Manager (APM)
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8 - F5 — BIG-IP Advanced Firewall Manager (AFM)
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8 - F5 — BIG-IP Application Security Manager (ASM)
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8 - F5 — BIG-IP Local Traffic Manager (LTM)
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8 - F5 — BIG-IP SSL Orchestrator
Vulnerable versions: 17.5.0-17.5.1; 17.1.0-17.1.2; 16.1.0-16.1.6; 15.1.0-15.1.10
Fixed in: 17.5.1.3; 17.1.3; 16.1.6.1; 15.1.10.8 - F5 — F5OS-A / F5OS-C
Vulnerable versions: Multiple versions
Fixed in: See F5 advisory K000156741 - F5 — BIG-IP Next SPK / CNF
Vulnerable versions: Multiple versions
Fixed in: See F5 advisory K000156741
Remediation for CVE-2025-53521
Patches
- F5 BIG-IP 17.5.x: Upgrade to 17.5.1.3
- F5 BIG-IP 17.1.x: Upgrade to 17.1.3
- F5 BIG-IP 16.1.x: Upgrade to 16.1.6.1
- F5 BIG-IP 15.1.x: Upgrade to 15.1.10.8
Immediate actions
- Apply F5 patches immediately: upgrade to 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8
- Check for IOCs: verify /usr/bin/umount and /usr/sbin/httpd hashes against known-good versions
- Review /var/log/restjavad-audit logs for unauthorized localhost iControl REST API access
- Check for presence of /run/bigtlog.pipe and /run/bigstart.ltm files
- Inspect /var/sam/www/webtop/renderer/ for modified PHP3 files (apm_css.php3, full_wt.php3, webtop_popup_css.php3)
- Isolate affected BIG-IP systems from the network pending investigation
- Block outbound DoH traffic to 1.1.1.1, 8.8.8.8, 9.9.9.9 from BIG-IP management interfaces
Workarounds
- Remove APM access policies from virtual servers if not required (eliminates attack surface)
- Restrict management plane access to trusted networks only
- Note: upgrading and rebooting removes attacker modifications from running partition
Longer-term hardening
- Deploy network detection for BRICKSTORM C2 patterns (HTTP/2 + WebSocket + Yamux multiplexing)
- Implement integrity monitoring on BIG-IP system binaries
- Restrict iControl REST API access to authorized management stations only
- Monitor for HTTP 201 responses with CSS content-type from BIG-IP systems
- Conduct full threat hunt across all F5 BIG-IP infrastructure
- Engage CISA-certified incident response provider for forensic investigation
CVEs associated with CVE-2025-53521
Weaknesses (CWE) in CVE-2025-53521
CWE-770
Timeline of CVE-2025-53521
- Estimated start of UNC5221 intrusion into F5 internal networks (12+ months before discovery in August 2025)
- F5 discovers unauthorized access to internal systems by sophisticated nation-state threat actor linked to China
- Google Mandiant publishes BRICKSTORM espionage campaign analysis identifying UNC5221 targeting tech and legal sectors
- F5 publishes security advisory K000156741 for CVE-2025-53521, initially classified as denial-of-service (CVSS 8.7)
- F5 releases patches for 24 vulnerabilities across BIG-IP, F5OS-A, F5OS-C, and BIG-IP Next platforms
- F5 publicly discloses breach by nation-state actor; confirms BIG-IP source code and vulnerability intelligence stolen (disclosure delayed under DOJ authorization)
- CISA, NSA, and FBI release BRICKSTORM Malware Analysis Report (AR25-338A) with IOCs and detection signatures from 12 samples
- CISA updates BRICKSTORM advisory with additional variant sample analysis and updated IOCs
- CISA publishes analysis of new BRICKSTORM variant with different capabilities than previously documented samples
- New information obtained confirming CVE-2025-53521 enables remote code execution, not just denial-of-service
- CISA adds CVE-2025-53521 to Known Exploited Vulnerabilities catalog with federal remediation deadline March 30, 2026
- F5 reclassifies CVE-2025-53521 from DoS to RCE; CVSS upgraded from 8.7 to 9.8 (v3.1) and 9.3 (v4.0); NVD entry updated
- Multiple security vendors confirm active exploitation of CVE-2025-53521 with BRICKSTORM backdoor deployment on customer systems
- CISA KEV remediation deadline for FCEB agencies; all federal civilian systems must have patches applied or mitigations in place
- UK NCSC publishes advisory; Dutch National Cyber Security Center (NCSC-NL) confirms observations of active abuse in Netherlands
- As of 2026-05-29, CVE-2025-53521 (F5 BIG-IP APM RCE, CVSS 9.8) remains live: it is in CISA KEV and under active exploitation, with 14,000+ instances still internet-exposed/unpatched per Shadowserver. China-nexus UNC5221 continues deploying BRICKSTORM undisrupted, no takedown, arrest, or successor reported.
Sources cited for CVE-2025-53521
- NCSC Advisory: Vulnerability affecting F5 BIG-IP APM
- F5 Security Advisory K000156741
- F5 Indicators of Compromise K000160486
- CISA KEV Entry CVE-2025-53521
- NVD Entry CVE-2025-53521
- CISA BRICKSTORM Malware Analysis Report AR25-338A
- DoD BRICKSTORM Backdoor Malware Analysis Report
- Google Mandiant: BRICKSTORM Espionage Campaign
- Help Net Security: Attackers exploiting RCE in BIG-IP APM
- The Hacker News: CISA Adds CVE-2025-53521 to KEV
- Resecurity: F5 BIG-IP Source Code Leak Tied to BRICKSTORM
- SecurityWeek: F5 Hack Linked to China
- ExtraHop: The BRICKSTORM Campaign UNC5221
- Picus Security: BRICKSTORM Malware UNC5221 Analysis
Threats related to CVE-2025-53521
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack-based Buffer Overflow
- F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State Actor
- BRICKSTORM Backdoor: UNC5221 PRC-Nexus APT Targeting VMware vSphere Infrastructure
- VerdantBamboo (UNC5221 / WARP PANDA) BRICKSTORM Campaign — MSP Supply-Chain Compromise of Edge Appliances with 18-Month Dwell
- Dell RecoverPoint Hardcoded Credentials RCE + UNC6201 GRIMBOLT Backdoor (CVE-2026-22769)
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access
Detection coverage for TL-2026-0297
As of 2026-03-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0297 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.