F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Summary

Malware targeting F5 BIG-IP Access Policy Manager appliances has been observed to inject a PHP web shell directly into the memory of running Apache processes. This technique allows the malware to evade detection by disk-based security scans, as the malicious code is not written to the file system.

IFF Assessment

FOE

This novel malware technique makes it harder for defenders to detect and remove malicious code, as it bypasses traditional file integrity checks.

Defender Context

Defenders should be aware of memory-resident malware techniques that bypass disk scanning. This highlights the need for enhanced memory forensics and runtime analysis capabilities to detect sophisticated threats that leave minimal on-disk artifacts.

Read Full Story →