נוזקה ב-F5 BIG-IP APM מזריקה Web Shell מבוסס PHP לזיכרון ומתחמקת מסריקות דיסק
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

◆ סיכום AI
נוזקה הקשורה לפריצות למכשירי F5 BIG-IP Access Policy Manager (APM) מחביאה Web Shell מבוסס PHP ישירות בזיכרון, במקום בקבצים בדיסק. גישה זו מאפשרת לנוזקה לחמוק מסריקות דיסק מסורתיות. הנוזקה מופעלת כאשר Apache טוען סקריפטים PHP של המכשיר, ומטמיעה את ה-Web Shell במופע הזיכרון שלהם.
# מהמקור
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are