Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Summary

Hackers have deployed a Linux rootkit that targets F5 BIG-IP APM devices. This rootkit can intercept PHP file loading and inject a fileless web shell into memory, bypassing the need to write malicious code to disk.

IFF Assessment

FOE

The discovery of a rootkit capable of stealthy in-memory infections on critical network devices represents a significant threat to defenders.

Severity

9.0 Critical (AI Estimated)

This score reflects a critical severity due to the potential for high impact on confidentiality, integrity, and availability, combined with an easy attack vector allowing for remote exploitation and the deployment of a rootkit which deeply compromises the system.

Defender Context

This incident highlights the critical need for continuous monitoring and timely patching of F5 BIG-IP APM devices, as attackers are actively exploiting vulnerabilities to deploy advanced persistent threats. Defenders should be vigilant for signs of in-memory persistence and fileless malware, and ensure robust logging and detection mechanisms are in place to identify such sophisticated attacks.

Read Full Story →