HackerFeeds

CyberSecurity News

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

The Hacker News
· September 9, 2026

AI summary

Malware targeting F5 BIG-IP Access Policy Manager appliances has been found to inject a PHP web shell into memory, allowing it to evade detection by disk scans. This malware hides the web shell in memory when Apache loads certain PHP scripts that are native to the appliances. The web shell is added to the in-memory copy of these scripts, making disk-based checks ineffective. The result is that a scan of the file on disk may not detect the malware. The affected scripts are part of the appliance's own functionality. Sophos published an analysis of this malware, detailing its behavior and evasion techniques.

Read the full article at The Hacker Newsthehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.