SECURITY·중요도 9·2026. 09. 09.·The Hacker News
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
── KO ──────────────────
F5 BIG-IP APM 기기에서 PHP 웹 셸이 메모리에 주입되어 디스크 스캔을 회피하는 악성 코드가 발견됨.
F5 BIG-IP Access Policy Manager 기기에서 발견된 악성 코드는 메모리에 PHP 웹 셸을 주입하여 디스크에 파일을 남기지 않고 숨깁니다. 이는 Sophos의 분석을 통해 밝혀졌으며, Apache가 해당 기기의 PHP 스크립트를 로드할 때 악성 코드가 메모리에 삽입됩니다. 이러한 방식은 디스크 스캔을 우회할 수 있게 도와줍니다.
── EN ──────────────────
Malware on F5 BIG-IP APM injects a PHP web shell into memory, evading disk scans.
Malware discovered on F5 BIG-IP Access Policy Manager devices injects a PHP web shell into memory, instead of leaving a file on disk. This was revealed in an analysis by Sophos, noting that when Apache loads the devices' PHP scripts, the malware inserts the web shell into the memory. This technique allows it to evade detection by disk scans.