Sophos found that malware tied to intrusions on F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory, allowing the infected files on disk to appear clean. The activity is linked to CVE-2025-53521 and the c05d5254 malware, with related reporting from F5 and ESETβs PoisonedRefresh analysis. #F5 #BIG-IP APM #CVE-2025-53521 #c05d5254 #PoisonedRefresh
Keypoints
- The web shell is injected into PHP code in memory instead of being stored on disk.
- F5 identified apm_css.php3, full_wt.php3, and webtop_popup_css.php3 as relevant indicators.
- The intrusion chain starts by infecting Apache and modifying how libphp loads files.
- The malware can also open a local socket and spawn /bin/bash for interactive access.
- Defenders should check memory, logs, integrity tools, and qkview reports, even after patching.
Read More: https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html