Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers
Brief
A stealthy Linux rootkit is giving attackers a new way to keep control of compromised F5 BIG-IP Access Policy Manager servers.
Instead of leaving an obvious malicious PHP file behind, it places a web shell only in the memory used by the running server process. The activity is linked to BIG-IP APM webtop environments running Apache and PHP.
F5 has associated related activity with CVE-2025-53521, an exploited, unauthenticated remote-code-execution flaw, a risk already highlighted in coverage of exposed BIG-IP APM devices .
Sophos analysts identified the implant while examining compromised systems. The researchers said its design points to a targeted second-stage payload, rather than a broad attack against ordinary Apache or content-management installations, and noted no evidence sufficient to attribute it to a named threat actor.
