A sophisticated malware campaign has been discovered targeting F5 BIG-IP Application Delivery Controllers (ADCs), leaving organizations vulnerable to web shell injections and potentially catastrophic data breaches. The malicious code, dubbed a “PHP web shell,” injects itself into system memory, evading detection by conventional disk-based scanning methods.
The attack vector leverages the vulnerabilities in BIG-IP APM (Access Policy Manager) systems, which are commonly used for secure authentication, authorization, and single sign-on (SSO) capabilities. These platforms play a critical role in managing access to sensitive corporate resources and applications. With over 20,000 BIG-IP installations worldwide, the potential impact of this malware campaign is substantial.
The malware works by exploiting a vulnerability that allows it to inject a PHP web shell into system memory. This malicious code then creates a backdoor for attackers to remotely access and control the compromised systems, bypassing traditional security controls like firewalls and intrusion detection systems (IDS). The most alarming aspect of this attack is its ability to evade disk-based scanning methods, making it significantly more difficult for organizations to detect and respond to the breach.
The implications of this malware campaign are far-reaching. A successful breach can lead to unauthorized access to sensitive data, disruption of critical business operations, and potentially severe reputational damage. Moreover, the fact that this attack injects a web shell into memory rather than on disk means that traditional security measures may be ineffective in detecting it.
The attacker’s ability to inject malware into system memory underscores the importance of implementing robust endpoint detection and response (EDR) solutions. EDR tools can identify and contain threats in real-time, even if they are lurking in system memory. Furthermore, organizations should prioritize regular vulnerability assessments and patch management for their BIG-IP systems to prevent exploitation.
In light of this discovery, it is essential for IT administrators and security teams to review their BIG-IP configurations and ensure that all necessary patches and updates have been applied. Regular monitoring of system logs and network activity can also help identify suspicious behavior indicative of a potential breach. By taking proactive steps to secure their systems and networks, organizations can significantly reduce the risk of falling victim to this malicious campaign.
Source: The Hacker News — 2026-09-09