Sophos uncovered a Linux rootkit in F5 BIG-IP APM environments that intercepts PHP loading and injects a fileless web shell directly into memory, keeping malicious code off disk. The malware appears to be a second-stage payload likely tied to CVE-2025-53521 and is also identified by ESET as PoisonedRefresh. #PoisonedRefresh #F5BIGIPAPM #CVE-2025-53521
Keypoints
- The rootkit targets F5 BIG-IP APM systems running Apache and PHP.
- It injects a web shell into memory without writing malicious files to disk.
- The malware likely followed exploitation of CVE-2025-53521.
- Sophos says the sample uses Linux and Apache-specific tradecraft, including hooks and RC4 obfuscation.
- Indicators include unusual PHP3 requests, modified SELinux settings, and a local UNIX socket backdoor.