As cited
Copy frozen at (site build).
breaches incidents
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Attackers have compromised F5 BIG-IP APM devices to install a Linux rootkit that intercepts PHP file loading and injects a fileless web shell into memory. This approach bypasses traditional disk-based detection methods by operating entirely in RAM.
Why it matters: Organizations running F5 BIG-IP APM are at risk of undetected web shell injection and command execution; detection requires memory-focused monitoring and immediate investigation of BIG-IP devices for unauthorized access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Attackers have compromised F5 BIG-IP APM devices to install a Linux rootkit that intercepts PHP file loading and injects a fileless web shell into memory. This approach bypasses traditional disk-based detection methods by operating entirely in RAM.
Why it matters: Organizations running F5 BIG-IP APM are at risk of undetected web shell injection and command execution; detection requires memory-focused monitoring and immediate investigation of BIG-IP devices for unauthorized access.
- Source published
- First seen by Cybersecurity Tracker