Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Sophos uncovered a Linux rootkit in F5 BIG-IP APM environments that intercepts PHP loading and injects a fileless web shell directly into memory, keeping malicious code off disk. The malware appears to be a second-stage payload likely tied to CVE-2025-53521 and is also identified by ESET as PoisonedRefresh. #PoisonedRefresh #F5BIGIPAPM #CVE-2025-53521

Keypoints

  • The rootkit targets F5 BIG-IP APM systems running Apache and PHP.
  • It injects a web shell into memory without writing malicious files to disk.
  • The malware likely followed exploitation of CVE-2025-53521.
  • Sophos says the sample uses Linux and Apache-specific tradecraft, including hooks and RC4 obfuscation.
  • Indicators include unusual PHP3 requests, modified SELinux settings, and a local UNIX socket backdoor.

Read More: https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/