F5 BIG-IP malware hides web shells in memory to evade detection

Published September 9, 2026

A stealthy malware hides inside F5 BIG-IP devices, running in memory so security tools can't find it. Attackers use this to secretly control the device without leaving files behind.

Report priority
Medium

How it works

  • Attackers install malware directly into the memory of F5 BIG-IP devices.
  • Since the malware doesn't save files to disk, traditional security scans miss it.
  • The malware then lets attackers send commands to the device without leaving traces that can be easily detected.

What to do

Check if you use F5 BIG-IP devices. If you manage or own these devices, you should verify if they have been compromised by this malware. Look for unusual network activity or unexpected changes in device behavior. If you suspect an issue, contact F5 support immediately.

Follow F5's official instructions to check for signs of infection and apply any recommended fixes. If you suspect your device is infected, isolate it from your network and contact F5 support for further assistance.

Technical details

Attackers exploit a vulnerability in F5 BIG-IP to inject malware into the device's memory. This malware acts like a hidden backdoor, allowing attackers to take control of the device's functions without leaving files that antivirus or security tools can detect.

Memory-resident malware targeting F5 BIG-IP appliances can evade file-based security defenses.