
In-Memory Linux Rootkit Targets F5 BIG-IP APM After CVE-2025-53521 Exploit
Sophos describes a second-stage Linux rootkit that targets F5 BIG-IP APM after CVE-2025-53521, hooking the Apache/PHP stack to load a memory-resident web shell, with an installer that corrupts SELinux and persists across upgrades; the malware hides strings with RC4, intercepts __libc_start_main, and creates a local UNIX socket for an interactive Bash shell, avoiding disk writes and using targeted PHP3 scripts to evade alerts, while ShadowServer notes hundreds of exposed endpoints.
