Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory – Help Net Security

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory – Help Net Security
Sophos found a rootkit on compromised F5 BIG-IP APM devices that hides a web shell in memory instead of writing it to disk, making it harder for file-based security tools to detect. The campaign is linked to exploited F5 BIG-IP APM activity, including CVE-2025-53521, and uses staged malware with deeper Apache and PHP interception techniques. #F5BIGIPAPM #CVE202553521 #PoisonedRefresh

Keypoints

  • The implant delivers web-shell-like access entirely in memory.
  • It targets Apache, libphp, APR, and BIG-IP APM webtop components.
  • F5 linked the activity to CVE-2025-53521 exploitation.
  • The malware was also identified by ESET as PoisonedRefresh.
  • Defenders should watch for suspicious .php3 requests and in-memory Apache or PHP behavior.

Read More: https://www.helpnetsecurity.com/2026/09/09/f5-big-ip-apm-rootkit-hides-web-shell-in-memory/