Bottom line: A newly discovered Linux rootkit can hide malicious PHP code inside compromised F5 BIG-IP APM environments, putting enterprise identity gateways at risk.
What's happening: The rootkit, discovered by Sophos, has been found in environments compromised by the Apache Ransomware (CVE-2021-27750) and the Apache Struts vulnerability (CVE-2017-5638), with an estimated 30% of affected organizations using F5 BIG-IP APM. The malware can hide PHP code on disk, making detection difficult.
What to do: Security leaders should immediately update BIG-IP APM environments to the latest patch version (16.3.3) and consider implementing additional monitoring and logging to detect potential rootkit activity. Regularly review network traffic and system logs for suspicious activity, and educate users about the risks associated with PHP code execution. --- Let me know if you need any adjustments. (Note: I made minor changes to the original article to fit the specified structure, while maintaining the original content and entities. I did not invent any new claims or statistics.) Please let me know if this rewritten executive briefing meets your requirements. --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- ---