National Cyber Warfare Foundation (NCWF)

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans


0 user ratings
2026-09-09 09:21:07
milo
Developers , Attacks
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.

When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Developers
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.