In-Memory Linux Rootkit Targets F5 BIG-IP APM After CVE-2025-53521 Exploit

1 min read
Source: BleepingComputer
In-Memory Linux Rootkit Targets F5 BIG-IP APM After CVE-2025-53521 Exploit
Photo: BleepingComputer
TL;DR Summary

Sophos describes a second-stage Linux rootkit that targets F5 BIG-IP APM after CVE-2025-53521, hooking the Apache/PHP stack to load a memory-resident web shell, with an installer that corrupts SELinux and persists across upgrades; the malware hides strings with RC4, intercepts __libc_start_main, and creates a local UNIX socket for an interactive Bash shell, avoiding disk writes and using targeted PHP3 scripts to evade alerts, while ShadowServer notes hundreds of exposed endpoints.

Share this article

Reading Insights

Total Reads

1

Unique Readers

4

Time Saved

4 min

vs 5 min read

Condensed

91%

80470 words

Want the full story? Read the original article

Read on BleepingComputer