Toggle light / dark theme

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.

The malware shows signs of being a second-stage payload that was likely deployed after exploiting CVE-2025–53521, a critical remote code execution (RCE) flaw that F5 Networks reclassified from a DoS problem in March.

Sophos researchers analyzed a sample and noted that, while it enables “on-demand server-side code execution” typically associated with webshells, it achieves this through “deeper Linux-and Apache-specific tradecraft.”

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */