<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit]]></title><description><![CDATA[<p dir="auto">Attackers have been observed breaching F5 BIG-IP Access Policy Manager (APM) devices to deploy a Linux rootkit designed to evade disk-based detection. The malware operates by intercepting PHP file loading processes and injecting a fileless web shell directly into memory, allowing persistent remote access without leaving malicious files on the filesystem.</p>
<p dir="auto">This technique is notable because it subverts the normal execution flow of the web application server, meaning that even routine file integrity checks may miss the compromise. The rootkit's in-memory payload enables attackers to maintain control over the affected BIG-IP APM appliance while avoiding common forensic signatures.</p>
<ul>
<li>The rootkit targets F5 BIG-IP APM environments.</li>
<li>It intercepts PHP file loading to inject the web shell.</li>
<li>The web shell is fileless, residing solely in memory.</li>
<li>No malicious code is written to the disk.</li>
</ul>
<p dir="auto">Given the privileged position of these devices in network infrastructure, successful exploitation could allow attackers to intercept or manipulate authentication traffic, potentially affecting broader access controls. Organizations running F5 BIG-IP APM should verify the integrity of their devices and review any unusual PHP activity or unexpected memory-resident processes.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Are any of you running F5 BIG-IP APM appliances — and if so, what detection measures are you using to spot memory-only implants like this rootkit?</p>
]]></description><link>https://xploitlk.com/topic/266/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:50:11 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/266.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 08 Sep 2026 22:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>