
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Security researchers have identified a Linux rootkit targeting F5 BIG-IP APM devices. The malware intercepts PHP file loading to inject a fileless web shell directly into memory, avoiding disk writes and traditional security controls. The origin and active exploitation status of the rootkit remain unconfirmed.
