Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers

A stealthy Linux rootkit is giving attackers a new way to keep control of compromised F5 BIG-IP Access Policy Manager servers. Instead of leaving an obvious malicious PHP file behind, it places a web shell only in the memory used by the running server process. The activity is linked to BIG-IP APM webtop environments running […]

This article has been indexed from Cyber Security News

Read the original article: