Rootkit hides web shells in F5 BIG-IP memory
Sophos says a tailored Linux rootkit lets attackers run web shells inside F5 BIG-IP APM without leaving malicious PHP on disk.
2 results for “apm”
Sophos says a tailored Linux rootkit lets attackers run web shells inside F5 BIG-IP APM without leaving malicious PHP on disk.
F5 BIG-IP APM malware hides a PHP web shell purely in memory, evading file checks, Sophos analysis shows.