F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Sophos found that malware tied to intrusions on F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory, allowing the infected files on disk to appear clean. The activity is linked to CVE-2025-53521 and the c05d5254 malware, with related reporting from F5 and ESET’s PoisonedRefresh analysis. #F5 #BIG-IP APM #CVE-2025-53521 #c05d5254 #PoisonedRefresh

Keypoints

  • The web shell is injected into PHP code in memory instead of being stored on disk.
  • F5 identified apm_css.php3, full_wt.php3, and webtop_popup_css.php3 as relevant indicators.
  • The intrusion chain starts by infecting Apache and modifying how libphp loads files.
  • The malware can also open a local socket and spawn /bin/bash for interactive access.
  • Defenders should check memory, logs, integrity tools, and qkview reports, even after patching.

Read More: https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html