CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6806

As cited

Copy frozen at (site build).

threat intel

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware targeting F5 BIG-IP Access Policy Manager appliances injects a PHP web shell into memory rather than storing it on disk, allowing it to evade disk-based detection scans. When Apache loads the appliance's PHP scripts, the malware adds the shell to the in-memory copy while leaving the disk files unmodified. Sophos disclosed this evasion technique on September 7, 2026.

Why it matters: Organizations running F5 BIG-IP APM are at immediate risk of undetected web shell access if compromised; memory-resident shells bypass standard file-scanning incident response procedures and require live memory inspection or network-based detection.

VendorsSophosF5
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary