The Files Look Clean. The F5 Appliance Could Still Be Backdoored.

Sophos found a rootkit that makes Apache execute a malicious version of legitimate BIG-IP APM files while the copies on disk remain clean.

Sophos found a rootkit that makes Apache execute a malicious version of legitimate BIG-IP APM files while the copies on disk remain clean.
© 2026 BlackTree. Independent technical publication.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
Jetpack's built-in visitor analytics. It records page views, referring sites, search terms, and outbound link clicks, and also carries the shared visitor-tracking library used by Jetpack Instant Search and WooCommerce Analytics.
Service URL: automattic.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.