Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
-
Attackers have been observed breaching F5 BIG-IP Access Policy Manager (APM) devices to deploy a Linux rootkit designed to evade disk-based detection. The malware operates by intercepting PHP file loading processes and injecting a fileless web shell directly into memory, allowing persistent remote access without leaving malicious files on the filesystem.
This technique is notable because it subverts the normal execution flow of the web application server, meaning that even routine file integrity checks may miss the compromise. The rootkit's in-memory payload enables attackers to maintain control over the affected BIG-IP APM appliance while avoiding common forensic signatures.
- The rootkit targets F5 BIG-IP APM environments.
- It intercepts PHP file loading to inject the web shell.
- The web shell is fileless, residing solely in memory.
- No malicious code is written to the disk.
Given the privileged position of these devices in network infrastructure, successful exploitation could allow attackers to intercept or manipulate authentication traffic, potentially affecting broader access controls. Organizations running F5 BIG-IP APM should verify the integrity of their devices and review any unusual PHP activity or unexpected memory-resident processes.
Source: BleepingComputer
Are any of you running F5 BIG-IP APM appliances — and if so, what detection measures are you using to spot memory-only implants like this rootkit?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login