Hackers Breach F5 BIG-IP APM Devices to Deploy Linux Rootkit
A sophisticated Linux rootkit targeting F5 BIG-IP APM environments can intercept PHP file loading and inject fileless web shells directly into memory.

According to BleepingComputer, hackers have successfully targeted devices within F5 BIG-IP APM environments to deploy a stealthy Linux rootkit, exploiting critical network infrastructure.
The malicious software is capable of intercepting PHP file loading processes and injecting a fileless web shell directly into memory, completely bypassing the need to write malicious code to the disk.
This fileless attack technique allows threat actors to evade traditional security solutions and remain undetected within compromised systems for extended periods, posing severe risks to enterprise networks.
For IT and security professionals, this incident highlights the critical importance of keeping network edge devices patched, closely monitored, and properly configured to defend against advanced persistent threats.



