Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
黑客入侵 F5 BIG-IP APM 设备并部署 Linux 根套件。该针对 F5 BIG-IP APM 环境的 Linux 根套件可拦截 PHP 文件加载,并将无文件 Web 壳直接注入内存,无需将恶意代码写入磁盘。
EVENT DOSSIER
On September 8, 2026, according to Bleeping Computer, hackers successfully infiltrated F5 BIG-IP APM devices and deployed a Linux root kit. This malware uses fileless attack techniques, directly injecting code into memory without writing it to disk. Its core functions include intercepting the loading of PHP files and implanting a fileless web shell into the target system’s memory, thereby achieving deep control over the F5 BIG-IP APM environment and persistent residency.
黑客入侵 F5 BIG-IP APM 设备并部署 Linux 根套件。该针对 F5 BIG-IP APM 环境的 Linux 根套件可拦截 PHP 文件加载,并将无文件 Web 壳直接注入内存,无需将恶意代码写入磁盘。