
highmalware
Sophos Reports Memory-Resident PHP Web Shell Injection on F5 BIG-IP APM Appliances
Sophos researchers have identified malware linked to break-in incidents that injects a PHP web shell into the memory of F5 BIG-IP Access Policy Manager (APM) appliances. The malicious code attaches to the appliance's own PHP scripts in memory when Apache loads them, leaving no persistent file on disk. This technique allows the web shell to evade traditional file-based security scans and forensic analysis. F5 has released security advisories and patches; administrators are urged to apply the latest firmware and monitor for indicators of compromise.
The Hacker News1 min read