In-Memory Linux Rootkit Targets F5 BIG-IP APM After CVE-2025-53521 Exploit

TL;DR Summary
Sophos describes a second-stage Linux rootkit that targets F5 BIG-IP APM after CVE-2025-53521, hooking the Apache/PHP stack to load a memory-resident web shell, with an installer that corrupts SELinux and persists across upgrades; the malware hides strings with RC4, intercepts __libc_start_main, and creates a local UNIX socket for an interactive Bash shell, avoiding disk writes and using targeted PHP3 scripts to evade alerts, while ShadowServer notes hundreds of exposed endpoints.
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit BleepingComputer
- Dissecting a PHP web server rootkit Sophos
- PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells gbhackers.com
- Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers CyberSecurityNews
- PoisonedRefresh Malware Hides Inside Apache Memory While F5 BIG-IP Files Stay Clean kobaran.com
Reading Insights
Total Reads
1
Unique Readers
4
Time Saved
4 min
vs 5 min read
Condensed
91%
804 → 70 words
Want the full story? Read the original article
Read on BleepingComputer