Home / Sep 10, 2026 / Story
0
#8 The Hacker News general September 09, 2026 at 07:36 UTC

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

By [email protected] (The Hacker News)

AI Summary

Sophos published a September 7 analysis detailing malware targeting F5 BIG-IP Access Policy Manager (APM) appliances that injects a PHP web shell directly into Apache's in-memory process, bypassing disk-based detection entirely. The malware hooks into three specific BIG-IP PHP scripts, meaning file integrity checks return clean results while the web shell remains active in memory. Organizations running F5 BIG-IP APM should implement memory-based detection and review Sophos's indicators of compromise immediately.

Relevance score: 84.0/100

# More from September 10