A sophisticated attack targeting F5 BIG-IP APM devices has surfaced, and it's the kind of threat that should concern any business relying on enterprise networking equipment — not just the large organisations that typically make the headlines. Hackers have been quietly breaching these widely used network access devices and planting what's known as a Linux rootkit: malicious software designed to hide itself deep inside a system, making it nearly invisible to standard security scans. If your business uses F5 BIG-IP hardware, or works with a managed service provider that does, this story deserves your attention.
What Is a Rootkit and Why Is It So Dangerous?
A rootkit is a type of malware that embeds itself at the lowest level of an operating system, effectively disguising its own presence. Unlike a typical virus that antivirus software can spot fairly easily, a rootkit is engineered to stay hidden — sometimes for months or years. Once installed, it gives attackers persistent, covert access to the compromised device. They can intercept network traffic, steal credentials, pivot deeper into your internal systems, and cover their tracks the whole time.
In this case, the target was F5's BIG-IP Access Policy Manager, a product used to control who can connect to a company's internal network and applications. Compromising this type of device is particularly damaging because it sits at the gateway of your entire network. An attacker who owns your access control system effectively owns your network.
Why This Attack Matters Even If You Don't Use F5 Devices
It's tempting to read a story like this and think it only applies to companies running specific hardware. But there are two reasons every SMB should pay attention here.
First, the ripple effect. Many small and mid-sized businesses rely on third-party IT providers, cloud platforms, or managed security services — and those providers often use enterprise-grade equipment like F5 BIG-IP. If your provider's infrastructure is compromised, so is the data flowing through it, including your employee credentials, customer records, and internal communications.
Second, the tactics used in this attack — exploiting a trusted network device to gain persistent, hidden access — are increasingly common across the threat landscape. Attackers are moving away from noisy, obvious intrusions and towards quiet, long-term footholds. By the time a breach is discovered, credentials and sensitive data are often already being traded on dark web markets.
How Stolen Credentials End Up on the Dark Web After an Attack Like This
When attackers gain access to a gateway device like F5 BIG-IP APM, one of the first things they harvest is authentication data — usernames, passwords, session tokens, and VPN credentials. This information is valuable because it allows attackers to log in as legitimate users rather than forcing their way in. It's quieter, harder to detect, and far more effective.
That harvested data doesn't always get used immediately. It frequently ends up packaged into infostealer dumps or sold through dark web credential markets, sometimes weeks after the initial breach. This is why monitoring what's circulating in those underground spaces matters so much. Your employees' login details could be sitting in a breach database right now, harvested from an attack that happened months ago, just waiting for someone to put them to use.
At Breachrr, we continuously scan breach databases, infostealer logs, dark web forums, public code repositories, and domain infrastructure to surface exactly this kind of exposure before it becomes an incident. We're not reacting to attacks after they happen — we're watching the spaces where stolen data lands.
What You Should Do Right Now
If your business uses F5 BIG-IP devices, contact your IT team or provider today and ask specifically whether those devices have been audited for signs of compromise, and whether firmware is current. If you use a managed service provider, ask them the same question about their own infrastructure.
More broadly, this F5 BIG-IP attack is a reminder that credential exposure is often the downstream consequence of sophisticated breaches — and that small businesses are not immune to the fallout. Taking ten minutes to understand your current exposure is a reasonable and practical first step.
Run a free audit at breachrr.com/audit to see what your business domain, employee emails, and company credentials look like from the outside. You might be surprised what's already out there.
Want to see if your company is exposed?