A Linux implant is distributed through compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows. F5 associates the related c05d5254 activity with BIG-IP APM systems affected by, an exploited unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server. The malware uses custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells.
The implant delivers a familiar outcome – on-demand server-side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache-specific tradecraft. The malware targets specific environments and leverages the target platform’s own runtime abstractions rather than fighting them. The threat actor uses a staged architecture, with an installer component responsible for deployment, persistence, and propagation, while the infected httpd component focuses on runtime capability, process manipulation, web shell delivery, and interactive access.[/subscribe_to_unlock_form]
A Linux implant is distributed through compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows. F5 associates the related c05d5254 activity with BIG-IP APM systems affected by, an exploited unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server. The malware uses custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells.
The implant delivers a familiar outcome – on-demand server-side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache-specific tradecraft. The malware targets specific environments and leverages the target platform’s own runtime abstractions rather than fighting them. The threat actor uses a staged architecture, with an installer component responsible for deployment, persistence, and propagation, while the infected httpd component focuses on runtime capability, process manipulation, web shell delivery, and interactive access.[emaillocker id="1283"]
The web shell does not need to exist in its final form on disk; instead, the implant alters how targeted PHP files are presented to the running process. Defenders should focus on correlation across layers, including network telemetry, protocol inspection, process monitoring, memory analysis, and integrity verification.
We recommend you to refer below link: https://my.f5.com/manage/s/article/K000156741
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1190 | Exploit Public | Facing Application- |
| Execution | T1203 | Exploitation for Client Execution | - |
| Persistence | T1505.003 | Server Software Component | Web Shell |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Defence Evasion | T1070.004 | Indicator Removal | File Deletion |
| Discovery | T1082 | System Information Discovery | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1105 | Ingress Tool Transfer | - |
The following reports contain further technical details:
[/emaillocker]