A newly discovered Linux rootkit, dubbed "Mango," is targeting F5 BIG-IP APM (Access Policy Manager) appliances by operating entirely in memory. The fileless attack technique allows it to evade conventional disk-based security scans and forensics.

First reported by BleepingComputer, the malware works by intercepting PHP file loading processes. It then injects a web shell directly into a running PHP process's memory. This approach leaves no malicious files on the device's disk, creating a significant blind spot for traditional security monitoring.

The threat is particularly acute due to the strategic role of BIG-IP APM appliances in network infrastructure. These systems handle critical user authentication and access policies. A compromise grants attackers a powerful position to harvest credentials, manipulate access controls, and pivot deeper into an organization's network.

Security analysis indicates Mango is the final-stage payload in a multi-step attack chain. Initial access is believed to occur via known vulnerabilities or credential theft, with the rootkit serving to establish a persistent and stealthy foothold.

Defending against this threat requires advanced strategies. Organizations are urged to deploy behavioral monitoring and Endpoint Detection and Response (EDR) solutions capable of runtime memory analysis. These tools are essential for spotting the anomalous PHP activity and network connections indicative of a Mango infection.

With no specific vendor advisory from F5 addressing this rootkit, the responsibility for defense lies with network administrators. Immediate actions include patching all BIG-IP systems, strictly limiting management interface access to internal networks, and proactively searching for indicators of compromise, treating appliances as high-risk points.

This incident highlights the escalating sophistication of attacks targeting core network infrastructure, demanding proactive and layered defenses.


新發現的 Linux rootkit「芒果」正透過完全在記憶體中運作的方式,針對 F5 BIG-IP APM(存取策略管理器)設備進行攻擊。此無檔案攻擊技術使其能規避傳統基於磁碟的安全掃描與取證調查。

據 BleepingComputer 首先報導,該惡意軟件透過攔截 PHP 檔案載入過程運作,隨後將 web shell 直接注入正在執行的 PHP 進程記憶體中。這種方法不會在設備磁碟上留下惡意檔案,為傳統安全監控製造了顯著盲點。

由於 BIG-IP APM 設備在基礎網路架構中扮演關鍵角色,此威脅尤為嚴峻。這些系統處理重要的用戶認證及存取策略,一旦被入侵,攻擊者將獲得強大立足點,用於收割憑證、操控存取控制權限,並進一步滲透進入組織內部網路。

安全分析指出,「芒果」是多階段攻擊鏈的最終載荷。初始入侵相信是透過已知漏洞或憑證竊取實現,而此 rootkit 則用於建立持久且隱匿的據點。

防禦此類威脅需採用進階策略。建議組織部署行為監控及端點偵測與回應(EDR)方案,使其具備運行時記憶體分析能力。這些工具對於偵測「芒果」感染特徵的異常 PHP 活動與網路連接至關重要。

由於 F5 未就此 rootkit 發布具體廠商公告,防禦責任落實在網路管理員身上。即時行動包括修補所有 BIG-IP 系統、嚴格限制管理介面僅允許內部網路存取,以及主動搜尋入侵指標,並視相關設備為高風險節點。

此次事件突顯針對核心網路基礎設施的攻擊正日益複雜化,需要積極主動且多層次的防禦策略。

新聞來源 / Original News Source