F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

September 9, 2026 1 Min Read 0
Threat Intelligence Brief

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Source: thehackernews.com
Threat Risk: High
Victim: Enterprise Organizations & Affected Platforms
Incident: F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Impact: Unauthenticated remote exploitation, data theft, or compromise of exposed infrastructure.
Attacker: Active Threat Actors / Exploitation Groups
Analysis: Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.

When Apache loads any of the three appliances’ own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are…
Recommendations: Apply emergency vendor updates, monitor network perimeters, and isolate vulnerable endpoints.; Review authentication logs for anomalous remote commands.
Source: The Hacker News

Editorial note: this post summarizes high-priority intelligence and links to primary telemetry.
View Primary Telemetry →

Leave a Reply

Your email address will not be published. Required fields are marked *