Interestana
Home/News/F5 BIG-IP APM Malware Hides PHP Web Shell in Memory
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

F5 BIG-IP APM Malware Hides PHP Web Shell in Memory

F5 BIG-IP APM Malware Hides PHP Web Shell in Memory

Malware associated with recent security breaches targeting F5 BIG-IP Access Policy Manager (APM) appliances has been observed to inject a PHP web shell directly into the system's memory, a technique designed to circumvent detection methods that rely on scanning files stored on disk. This sophisticated evasion tactic was detailed in an analysis published by cybersecurity firm Sophos on September 7. The malware operates by intercepting the Apache web server's process when it loads specific, legitimate PHP scripts that are integral to the BIG-IP appliance's functionality. By injecting the malicious web shell into the in-memory representation of these scripts, the malware ensures that a file system scan would not reveal any unauthorized code, as the web shell exists only in volatile memory. This method effectively blinds traditional file integrity monitoring and antivirus solutions that primarily focus on disk-based artifacts. The specific PHP scripts targeted by this malware are part of the BIG-IP appliance's own operational code, making their loading a routine and expected process for the web server. This allows the malware to blend in with normal system activity, further complicating detection efforts. The ability to execute commands remotely through this in-memory web shell grants attackers a persistent foothold within the compromised appliance, enabling them to conduct further reconnaissance, exfiltrate sensitive data, or deploy additional malicious payloads. The F5 BIG-IP APM is a widely used solution for managing and securing access to applications and network resources, making compromises of this system particularly impactful. Attackers leveraging this technique can potentially gain unauthorized access to the applications and data protected by the BIG-IP APM, including user credentials, session information, and sensitive corporate data. The Sophos analysis highlights the evolving nature of malware designed to bypass security controls, emphasizing the need for security solutions that incorporate memory analysis and behavioral detection capabilities in addition to traditional file-based scanning. Organizations utilizing F5 BIG-IP APM appliances are advised to review their security configurations, monitor system logs for anomalous activity, and ensure they are applying the latest security patches and updates from F5 Networks to mitigate the risk of such sophisticated attacks. The implications of this attack vector extend to the broader cybersecurity landscape, underscoring the persistent threat posed by advanced persistent threats (APTs) and the continuous arms race between attackers and defenders in the digital realm. The evasion of disk scans by residing solely in memory represents a significant challenge for incident response teams, requiring specialized tools and expertise to identify and neutralize such threats effectively. The specific details of the malware's operational flow and the exact PHP scripts targeted, while not fully disclosed by Sophos to prevent further exploitation, point to a deep understanding of the F5 BIG-IP APM architecture by the attackers.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next