As cited
Copy frozen at (site build).
threat intel
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Malware targeting F5 BIG-IP Access Policy Manager appliances injects a PHP web shell into memory rather than storing it on disk, allowing it to evade disk-based detection scans. When Apache loads the appliance's PHP scripts, the malware adds the shell to the in-memory copy while leaving the disk files unmodified. Sophos disclosed this evasion technique on September 7, 2026.
Why it matters: Organizations running F5 BIG-IP APM are at immediate risk of undetected web shell access if compromised; memory-resident shells bypass standard file-scanning incident response procedures and require live memory inspection or network-based detection.
- Source published
- First seen by Cybersecurity Tracker