← Back to Feed

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

September 8, 2026 · BleepingComputer · Severity: MEDIUM

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a PHP web shell into memory. The malware operates entirely in memory, leaving minimal forensic traces on the filesystem. The web shell enables attackers to execute arbitrary commands on the compromised device.

Key Takeaways

  • Active exploitation detected — patch immediately to prevent compromise
  • Affected systems should be identified and prioritized for remediation
  • Monitor for additional indicators of compromise as investigations evolve
☕ Buy a Coffee