Microsoft just published the play-by-play of how attackers walked from an exposed F5 BIG-IP all the way into Kerberos territory, and the malware budget for the entire operation looks suspiciously close to zero. Palo Alto’s Unit 42 says nation-state crews are now openly using ROADtools, the same open-source recon framework that has powered red team engagements for years. Cloud Atlas dropped a new payload but kept the persistence stack boring: SSH, Tor, and a SOCKS proxy. The theme of this week’s cybersecurity reporting is unmistakable. Attackers are showing up with your tools, your appliances, and your own admin credentials, and they’re hoping you can’t tell the difference.
They’re right more often than they should be.
Your Recon Framework Is Doing Recon On You
ROADtools has been a red team staple for years. It’s a clean, well-documented framework for enumerating Entra ID (formerly Azure AD), built by a respected researcher and adopted across pentesting shops. So when Unit 42 published its writeup this week titled Paved With Intent, it wasn’t reporting a novel malware family. It was reporting that real threat actors are now running the same toolkit the defenders’ offensive teams use, against the same tenants, hitting the same Graph API endpoints.
This is a brutal problem for threat detection. The traffic looks like a legitimate Azure admin session because it is legitimate Azure admin tooling. The OAuth flow is normal. The Graph calls are valid. The user agent strings can be trivially adjusted. Your EDR sees nothing because nothing executes on an endpoint you control. Your identity logs see what looks like an unusually thorough audit by someone with global reader.
The structural lesson is that any tool useful enough for legitimate cloud administration is useful enough for cloud intrusion. Treating “open-source recon framework” as a marker of malicious intent is over a decade out of date. The detection has to live at the behavior layer: which identities run heavy enumeration, against which directories, at which times, from which networks. Nobody is going to flag roadrecon by name. The activity pattern is the signal.
Edge Appliances Are Pre-Authenticated Pivot Points
The Microsoft writeup on the F5-to-Confluence chain is worth reading slowly because it’s a near-perfect anatomy of a modern intrusion. The starting point was an internet-facing F5 BIG-IP that was, in Microsoft’s careful phrasing, “exposed.” From there the attacker pivoted to an internal Confluence server, harvested credentials from page attachments and integration tokens, and made a credible run at Kerberos relay and lateral movement.
Three things in that sentence deserve attention.
First, the F5 wasn’t doing anything weird. It was doing its job, which is to terminate traffic at the edge of your network. The fact that it had a known-bad exposure made it a beachhead, but once the attacker was through it, the device’s normal function as a privileged piece of infrastructure did the heavy lifting.
Second, Confluence on the inside is a credential vending machine. Every team posts runbooks, every runbook quotes a secret, every secret rotation lags the documentation by months. Pivoting from a compromised edge appliance to an internal wiki is the path of least resistance in almost every enterprise.
Third, the Kerberos relay attempt shows what attackers actually do once they’re inside a Windows-shop. They reach for the identity fabric. The cyber security model that imagines an attacker still rattling endpoint doors after a successful pivot is comforting and wrong.
Cybersecurity When The Attackers Bring Nothing New
Cloud Atlas has been around long enough to qualify for a pension. Kaspersky’s update this week describes a fresh implant called PowerCloud, but the persistence and lateral movement parts of the writeup are almost dull: SSH for command channels, ReverseSocks for tunneling, Tor for hiding the exit. None of that triggers a signature. None of it requires zero-days. It’s just admin tooling, wired up for someone who isn’t an admin.
That’s the part of cybersecurity strategy that defenders keep underestimating. The interesting payload gets the headline, but the persistence layer is what makes the intrusion expensive to evict. And the persistence layer increasingly looks like a slightly weirder version of your own sysadmin stack. If your hunting hypothesis is “we’ll catch the novel binary,” you have set yourself up to catch maybe five percent of what matters.
The defense in depth answer is not new, but it’s underbuilt almost everywhere. Behavioral baselines on identity, telemetry on east-west traffic, egress controls that actually care where SSH and Tor sessions terminate, and threat detection rules that fire on combinations of normal things, not on the presence of any single bad thing. None of that ships in a box. All of it requires the boring discipline of knowing what normal looks like in your environment.
What To Actually Do This Week
If you read the Microsoft, Unit 42, and Kaspersky writeups back-to-back, a short list of practical defensive moves emerges. None of them require new procurement.
- Baseline Graph API and directory enumeration. Know which service principals and accounts read the directory, how often, and how much. Alert on first-time-ever bulk reads, regardless of the tool that issued them.
- Treat edge appliances as compromised-in-waiting. Put them behind their own segment, log their outbound connections, and assume a successful exploit moves laterally within the hour. Your firewall ruleset for the edge segment should look paranoid.
- Audit Confluence, SharePoint, and wiki content for live secrets. Run a credential scanner against the internal knowledge base monthly. Rotate anything that turns up. The brute-force phase of the next breach starts with the credentials your team helpfully indexed.
- Egress filter SSH, SOCKS, and Tor by default. Servers don’t need to make arbitrary outbound SSH connections. Workstations don’t need to reach Tor exits. The Cloud Atlas persistence stack collapses when egress is restrictive.
- Inventory dual-use tooling. If your red team uses ROADtools, BloodHound, or any cloud recon framework, your blue team needs detections that work whether the actor is you or them.
- Rehearse an incident response scenario where no malware is found. If your IR playbook depends on a hash to scope blast radius, the next intrusion will outrun you. Practice scoping by identity and session activity instead.
- Tighten security hardening on identity infrastructure. Kerberos relay attempts succeed because LDAP signing and channel binding remain off. Turn them on. Audit who has unconstrained delegation. Cut it.
The CISA contractor’s accidental GovCloud key dump, which lawmakers are now demanding answers about, sits at the edge of this same problem. A trusted person with legitimate access produced the worst possible outcome through normal tools. Threat-protection programs built around suspicious-binary alerting do not catch any of that. The agencies still struggling to figure out which of their secrets are burned are getting a very public lesson in why credential inventory beats credential rotation.
Sources
- Paved With Intent: ROADtools and Nation-State Tactics in the Cloud (Unit 42)
- From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence (Microsoft)
- Cloud Atlas activity in the second half of 2025 and early 2026 (Securelist)
- Lawmakers Demand Answers as CISA Tries to Contain Data Leak (KrebsOnSecurity)
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
