Linux Rootkit Exploits F5 BIG‑IP APM to Implant Fileless Web Shell
A newly discovered Linux rootkit is targeting F5 Networks' BIG‑IP Access Policy Manager (APM) devices, allowing attackers to hijack PHP file loading processes and inject a fileless web shell directly into system memory.
The malicious code operates without ever writing executable files to disk, a technique that helps it evade traditional antivirus and host‑based intrusion detection tools that rely on file signatures. By residing solely in RAM, the rootkit can maintain persistence and execute commands while remaining largely invisible to standard forensic methods.
BIG‑IP APM appliances are widely deployed in corporate and data‑center environments to manage user authentication, single sign‑on, and traffic encryption. Their central role in handling web applications makes them attractive targets for adversaries seeking to gain footholds within enterprise networks.
Security researchers who first uncovered the rootkit noted that it intercepts the PHP interpreter's file‑include routine, substituting malicious payloads for legitimate scripts. This enables the attacker to run arbitrary commands on the compromised host, potentially facilitating lateral movement, data exfiltration, or further exploitation of connected systems.
While the specific campaign details remain limited, analysts warn that the fileless approach represents an evolving threat landscape where attackers prioritize stealth over brute‑force tactics. Organizations using BIG‑IP APM are advised to review patch levels, monitor for anomalous memory activity, and enforce strict network segmentation to limit exposure.
F5 Networks has not yet issued an official statement regarding the rootkit, but the company historically releases security advisories and firmware updates in response to critical vulnerabilities. Administrators should stay alert for forthcoming guidance and consider employing endpoint detection and response solutions capable of detecting in‑memory anomalies.
Comments (0)
Be the first to comment.
Join the discussion