<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Memory-Injection on CuraSec</title><link>https://curasec.metacog.co.kr/tags/memory-injection/</link><description>Recent content in Memory-Injection on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 09 Sep 2026 15:05:56 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/memory-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>F5 BIG-IP APM Malware Hides PHP Web Shell in Memory to Evade Disk Scans</title><link>https://curasec.metacog.co.kr/insights/2026-09-09-f5-big-ip-apm-malware-injects-a-php-web-shell-into-memory-ev/</link><pubDate>Wed, 09 Sep 2026 15:05:56 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-09-f5-big-ip-apm-malware-injects-a-php-web-shell-into-memory-ev/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> F5 BIG-IP APM is a widely-deployed enterprise edge appliance and the malware is linked to confirmed break-ins; disk-based file integrity checks won&amp;rsquo;t detect this web shell, so audit BIG-IP APM instances using network-based IOCs and memory forensics from the Sophos September 7 analysis.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of an edge appliance combined with a memory-resident web shell means EDR and file-scan detections will miss it; assume-breach posture applies — hunt using any network or request-pattern IOCs from the Sophos report and flag all BIG-IP APM devices for manual inspection.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If your organization runs F5 BIG-IP APM, direct the security team to perform a compromise assessment this week — the memory-evasion technique means standard monitoring may have already missed a breach on this access gateway.&lt;/li>
&lt;/ul></description></item></channel></rss>