← Blog · · df00tech

F5 BIG-IP APM Devices Hit With Fileless Linux Rootkit That Hijacks PHP Loading

security-news technique

What happened

According to BleepingComputer, attackers have breached F5 BIG-IP Access Policy Manager (APM) devices and deployed a Linux rootkit designed to intercept PHP file loading. The rootkit reportedly injects a fileless web shell directly into memory rather than writing malicious code to disk, allowing it to persist and operate while evading traditional disk-based detection.

Why it matters for defenders

F5 BIG-IP APM appliances sit at the network edge and broker authentication and access control for enterprise applications, making them a high-value target — compromise can translate directly into broad access to internal resources. A fileless, memory-resident implant that hooks PHP loading is also harder to spot with standard file-integrity monitoring or antivirus scanning, since there's no malicious binary sitting on disk to find. Organizations running BIG-IP APM with PHP-based components in their management or access workflows should treat this as a live threat to edge infrastructure.

What defenders should watch for or do now

  • Review BIG-IP APM systems for unexpected process behavior, unusual memory usage patterns, or unexplained PHP execution anomalies.
  • Hunt for signs of tampering with the PHP runtime or loader on affected devices rather than relying solely on file-hash or disk-based scanning.
  • Audit network access logs for unusual outbound connections or web-shell-style HTTP request patterns from BIG-IP management interfaces.
  • Ensure BIG-IP APM devices are on current, supported firmware and follow F5's official security advisories closely, since specifics of the intrusion vector have not yet been detailed in initial reporting.
  • Consider memory forensics or reboot-based volatility checks on suspect devices, since fileless implants may not survive a clean restart.

Developing story

This is early reporting on a net-new technique, and technical details — including the initial access vector, threat actor attribution, and scope of affected deployments — have not been fully disclosed. Defenders should treat this analysis as preliminary and monitor for updates. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.