
CriticalF5 BIG-IP Access Policy Manager (APM)
Linux rootkit on F5 BIG-IP APM hides its web shell in memory
Sophos X-Ops has dissected a Linux implant found on compromised F5 BIG-IP APM appliances. It hooks Apache and PHP to inject a web shell into memory, leaving the scripts on disk untouched, and opens a second backdoor over a local UNIX socket.
