Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Data Breaches & Incidents
  5. Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Scheduled Pinned Locked Moved Data Breaches & Incidents
linux
1 Posts 1 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Attackers have been observed breaching F5 BIG-IP Access Policy Manager (APM) devices to deploy a Linux rootkit designed to evade disk-based detection. The malware operates by intercepting PHP file loading processes and injecting a fileless web shell directly into memory, allowing persistent remote access without leaving malicious files on the filesystem.

    This technique is notable because it subverts the normal execution flow of the web application server, meaning that even routine file integrity checks may miss the compromise. The rootkit's in-memory payload enables attackers to maintain control over the affected BIG-IP APM appliance while avoiding common forensic signatures.

    • The rootkit targets F5 BIG-IP APM environments.
    • It intercepts PHP file loading to inject the web shell.
    • The web shell is fileless, residing solely in memory.
    • No malicious code is written to the disk.

    Given the privileged position of these devices in network infrastructure, successful exploitation could allow attackers to intercept or manipulate authentication traffic, potentially affecting broader access controls. Organizations running F5 BIG-IP APM should verify the integrity of their devices and review any unusual PHP activity or unexpected memory-resident processes.

    Source: BleepingComputer

    Are any of you running F5 BIG-IP APM appliances — and if so, what detection measures are you using to spot memory-only implants like this rootkit?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World