Invisible Shadows: New Linux Rootkit Haunts F5 BIG-IP Devices
Security researchers have discovered a sophisticated Linux rootkit targeting F5 BIG-IP Access Policy Manager (APM) devices. This malware operates by intercepting the loading process of PHP files to inject a fileless web shell directly into the device's memory. By avoiding the creation of files on the physical disk, the attack significantly reduces its footprint, making detection by traditional security tools extremely difficult. The rootkit allows attackers to maintain persistent access and execute remote commands while remaining hidden within the system's core processes.