#8
The Hacker News
general
September 09, 2026 at 07:36 UTC
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
By [email protected] (The Hacker News)
AI Summary
Sophos published a September 7 analysis detailing malware targeting F5 BIG-IP Access Policy Manager (APM) appliances that injects a PHP web shell directly into Apache's in-memory process, bypassing disk-based detection entirely. The malware hooks into three specific BIG-IP PHP scripts, meaning file integrity checks return clean results while the web shell remains active in memory. Organizations running F5 BIG-IP APM should implement memory-based detection and review Sophos's indicators of compromise immediately.
Relevance score: 84.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →