Interestana
Home/News/Hackers Deploy Linux Rootkit on F5 BIG-IP APM Devices
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Hackers Deploy Linux Rootkit on F5 BIG-IP APM Devices

Cybersecurity researchers have identified a sophisticated Linux rootkit specifically targeting devices running F5 BIG-IP Application Policy Manager (APM). This malware is designed to intercept PHP file loading processes and inject a fileless web shell directly into the device's memory. This technique allows attackers to maintain persistence and execute commands without writing any malicious code to the disk, making it significantly harder for traditional security tools to detect and remove.

The rootkit exploits vulnerabilities within the F5 BIG-IP APM environment, a widely used solution for managing application access and security. By compromising these devices, attackers gain a powerful vantage point to monitor and manipulate traffic, potentially leading to data exfiltration, further network compromise, or denial-of-service attacks. The fileless nature of the web shell is a critical advancement in attack methodologies, as many security solutions rely on scanning file systems for known malware signatures. In this scenario, the malicious payload exists only in volatile memory, disappearing upon device reboot unless the rootkit itself ensures its re-injection. This necessitates advanced memory forensics and behavioral analysis for detection.

While the specific entry vector for the initial compromise is not detailed, the subsequent deployment of the rootkit and web shell highlights a significant threat to organizations relying on F5 BIG-IP APM for secure application access. The ability to inject code directly into the memory of a critical network appliance like BIG-IP APM allows attackers to bypass standard security controls, including intrusion detection systems (IDS) and antivirus software that primarily focus on file-based threats. The implications are far-reaching, as compromised APM devices can serve as a pivot point into an organization's internal network, granting attackers access to sensitive data and systems that would otherwise be protected.

This development underscores the evolving landscape of cyber threats, where attackers are increasingly leveraging advanced techniques to evade detection. The reliance on fileless malware and in-memory execution poses a substantial challenge for security teams. Organizations using F5 BIG-IP APM are strongly advised to review their security configurations, ensure all systems are patched with the latest security updates, and implement robust monitoring and incident response plans that include memory analysis capabilities. Proactive threat hunting and a defense-in-depth strategy are crucial to mitigating the risks associated with such sophisticated attacks. The continuous innovation in both attack and defense mechanisms within the cybersecurity domain necessitates ongoing vigilance and adaptation from security professionals worldwide.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next