CyberSingle-sourceHighDevelopingFeatured
7.0
F5 BIG-IP APM devices breached; Linux rootkit injects fileless web shell
Threat actors are exploiting F5 BIG-IP APM devices to deploy a Linux rootkit that intercepts PHP file loading and injects a fileless web shell into memory, evading disk-based detection. The attack chain and initial access vector remain partially unconfirmed, but the technique indicates a sophisticated, stealthy campaign targeting network edge infrastructure. This matters because compromised BIG-IP devices can serve as a pivot point for lateral movement and persistent access within enterprise networks.
Score Breakdown
Mosaic Score7.0
Confidence0.5
Significance0.8
Source credibility0.5