- What: F5 BIG-IP appliances targeted by memory-resident malware
- Impact: Network infrastructure at risk of compromise
Network Security , Malware F5 BIG-IP malware hides web shells in memory to evade detection September 9, 2026 Share By Steve Zurier (Adobe Stock Image) Stealthy malware tied to break-ins on F5 BIG-IP Access Policy Manager (APM) appliances let attackers hide PHP web shells in memory as opposed to a file on disk. In a Sept. 7 blog post , Sophos said what’s different here is that the malware demonstrates advanced techniques to evade detection, such as custom executable and linking format (ELF) loading, function hooking, and runtime code patching. The researchers said the results are familiar to what we’ve seen on other attacks on network infrastructure: on-demand server-side code execution commonly associated with web shells but implemented using deeper Linux and Apache-specific tradecraft. Damon Small, a board member at Xcape, explained that traditional defenses often depend on detecting changes to files written to disk. By existing solely in memory, Small said those controls are left ineffective. “Therefore, defenders need to become more sophisticated just as the adversary has by monitoring not just file activity, but processes that are active in memory,” said Small. “This can be achieved through advanced products that monitor active processes in memory and can stop those that are unauthorized from running.” Rogier Fischer, co-founder and CEO at Hadrian, added that by interfering with the way Apache and PHP load legitimate BIG-IP files and injecting the web shell into the version held in memory, the malware makes it harder for defenders to identify a compromise. Fischer said the consequences are serious because a web shell effectively gives an attacker a way to send commands to the compromised appliance through web requests. “This makes mitigating exposure a priority for security teams, but patching alone is not enough if the appliance may already have been compromised,” said Fischer. “Where teams cannot establish confidence that an exposed appliance is clean, rebuilding it from a trusted state may be safer than relying solely on conventional malware scans.” John Strand, owner of Black Hills Information Security, said the F5 BIG-IP vulnerability involving a web shell that exists in memory isn’t really a new technique: Memory-resident malware has been around for an incredibly long time. It goes all the way back to advanced research like Shadow Walker, which was presented at Black Hat years ago. “What makes this interesting, and frankly pretty insidious, is where it’s running,” said Strand. “With desktops and servers, we’ve built an entire security ecosystem around EDR. We expect agents to be there scanning memory, collecting telemetry, looking at processes, and identifying unusual behavior. With appliances like these, you often don’t have that. There simply aren’t a lot of EDR products you can drop onto a network appliance and expect the same level of visibility.” Strand said there’s another concern with memory-resident attacks against specialized appliances. If an attacker gets sufficient privileges, Strand said there’s the potential to move deeper into the device, including firmware. “At that point, eradication can become incredibly difficult,” said Strand. “Once we get off the shiny, happy path of standard desktops and servers, a lot of the security capabilities we take for granted start disappearing. Visibility, blocking, telemetry, memory analysis, and endpoint detection may simply not exist. That’s what makes attacks against these appliances particularly dangerous.” Sam Decker, threat intelligence engineer at Blackpoint Cyber, added that most web shells are just a file sitting in the web root, easy enough to catch when antivirus or endpoint monitoring watches the disk. Decker said network appliances typically don't have that kind of monitoring, so there's no scan to evade in the first place. “This malware goes further still, patching the Apache binary and hooking the PHP module loader so the web shell gets spliced into legitimate scripts only when they load into memory,” said Decker. “Even someone who did check the disk would find everything looking stock, since the malicious code was never written there to begin with.” An In-Depth Guide to Network Security Get essential knowledge and practical strategies to fortify your network security. Learn More Steve Zurier Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area. Related Network Security MikroTik routers targeted by active SSH zero-day exploitation SC Staff September 8, 2026 The MikroTrick attack chain exploits two critical vulnerabilities: CVE-2026-67276, an SSH authentication bypass, and CVE-2026-86060, an SSH session privilege escalation. Network Security Cisco addresses critical vulnerabilities in Nexus 9000 switches and IOS XR SC Staff September 4, 2026 The critical Nexus vulnerability (CVE-2026-20212) allows unauthenticated attackers to execute code with root privileges by binding to an unrestricted IP address and reaching TCP ports 43210 and 43211. Network Security HPE patches ArubaOS-CX switches vulnerable to remote code execution Steve Zurier September 4, 2026 HPE patched 35 ArubaOS-CX flaws, including a critical bug that could enable remote code execution. Related Events Cybercast Network security: Adaptive defense, SASE, and micro-segmentation Tue Oct 13 Cybercast How to transform your SOC through XDR and MDR On-Demand Event Cybercast AI for network security: Problems and solutions On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms ACK Piggybacking Address Resolution Protocol (ARP) Bastion Host Computer Network Crossover Cable Cut-Through Demilitarized Zone (DMZ) Distance Vector Domain Name Dynamic Routing Protocol You can skip this ad in 5 seconds