Sophos found Linux malware targeting F5 BIG-IP APM that injects a PHP web shell into Apache memory, helping attackers evade file-based detection.
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs ...