A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises, financial institutions, government agencies, and public sector organizations. “The implant delivers a familiar outcome – on-demand server-side code execution commonly associated with web shells – but implements … More
The post Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory appeared first on Help Net Security.