Hackers breach some F5 BIG-IP APM systems and deploy a Linux rootkit that enables server-side code execution. Security reporting says the malware can intercept how PHP files are loaded and then inject a web shell that runs directly from memory, reducing or eliminating the need to write malicious components to disk.

Both outlets cite this memory-focused approach as a key feature of the compromise. Help Net Security attributes analysis to Sophos and describes F5 BIG-IP APM as an access policy enforcement product used by enterprises and government organizations to secure access to applications, APIs, and data. Bleeping Computer similarly characterizes the implant as a Linux rootkit targeting environments using BIG-IP APM.

The sources do not fully align on all technical specifics beyond the shared behaviors—rootkit presence, PHP-loading interception, and an in-memory web shell—nor do they present the same breadth of affected-system details. The common theme across reporting is that the attack is designed to maintain control while making disk-based detection harder.