Sophos found a rootkit on compromised F5 BIG-IP APM devices that hides a web shell in memory instead of writing it to disk, making it harder for file-based security tools to detect. The campaign is linked to exploited F5 BIG-IP APM activity, including CVE-2025-53521, and uses staged malware with deeper Apache and PHP interception techniques. #F5BIGIPAPM #CVE202553521 #PoisonedRefresh
Keypoints
- The implant delivers web-shell-like access entirely in memory.
- It targets Apache, libphp, APR, and BIG-IP APM webtop components.
- F5 linked the activity to CVE-2025-53521 exploitation.
- The malware was also identified by ESET as PoisonedRefresh.
- Defenders should watch for suspicious .php3 requests and in-memory Apache or PHP behavior.
Read More: https://www.helpnetsecurity.com/2026/09/09/f5-big-ip-apm-rootkit-hides-web-shell-in-memory/