Threat Advisory

BIG-IP APM Malware Gains Execution and Deploys PHP Web Shell

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Linux implant is distributed through compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows. F5 associates the related c05d5254 activity with BIG-IP APM systems affected by, an exploited unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server. The malware uses custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells.

The implant delivers a familiar outcome – on-demand server-side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache-specific tradecraft. The malware targets specific environments and leverages the target platform’s own runtime abstractions rather than fighting them. The threat actor uses a staged architecture, with an installer component responsible for deployment, persistence, and propagation, while the infected httpd component focuses on runtime capability, process manipulation, web shell delivery, and interactive access.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Linux implant is distributed through compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows. F5 associates the related c05d5254 activity with BIG-IP APM systems affected by, an exploited unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server. The malware uses custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells.

The implant delivers a familiar outcome – on-demand server-side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache-specific tradecraft. The malware targets specific environments and leverages the target platform’s own runtime abstractions rather than fighting them. The threat actor uses a staged architecture, with an installer component responsible for deployment, persistence, and propagation, while the infected httpd component focuses on runtime capability, process manipulation, web shell delivery, and interactive access.[emaillocker id="1283"]

The web shell does not need to exist in its final form on disk; instead, the implant alters how targeted PHP files are presented to the running process. Defenders should focus on correlation across layers, including network telemetry, protocol inspection, process monitoring, memory analysis, and integrity verification.

RECOMMENDATION:

We recommend you to refer below link: https://my.f5.com/manage/s/article/K000156741

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Execution T1203 Exploitation for Client Execution -
Persistence T1505.003 Server Software Component Web Shell
Persistence T1543.003 Create or Modify System Process Windows Service
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Defence Evasion T1070.004 Indicator Removal File Deletion
Discovery T1082 System Information Discovery -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1105 Ingress Tool Transfer -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu