Cybersecurity researchers have uncovered a sophisticated new malware campaign that is changing how attackers compromise enterprise systems. The newly discovered Linux Rootkit F5 BIG-IP APM malware targets vulnerable F5 BIG-IP Access Policy Manager (APM) appliances and introduces a stealth technique rarely seen in enterprise attacks. Instead of storing malicious PHP files on the server, the malware injects its web shell directly into the memory of the Apache web server, making it extremely difficult to detect using traditional security tools.
The discovery, made by Sophos X-Ops, highlights a growing trend in modern cyberattacks where threat actors avoid leaving traces on the filesystem. Since many organizations rely on antivirus software and file integrity monitoring to detect malware, a memory-only attack can remain hidden for extended periods while giving attackers persistent access to sensitive systems.
Security researchers believe the malware is deployed after attackers exploit CVE-2025-53521, a critical remote code execution vulnerability affecting F5 BIG-IP APM devices. Although Sophos has not attributed the campaign to any specific threat group, the complexity of the malware indicates that it was designed for targeted attacks against enterprise environments rather than mass exploitation.
What Is the Linux Rootkit F5 BIG-IP APM?
The Linux Rootkit F5 BIG-IP APM is an advanced post-exploitation malware designed specifically for compromised F5 BIG-IP Access Policy Manager appliances. Unlike traditional Linux malware, which often creates suspicious executable files or modifies web scripts, this rootkit operates almost entirely in memory.
Its primary objective is to maintain long-term access to compromised servers while remaining invisible to conventional security solutions. Once installed, the malware quietly monitors Apache until the PHP module is loaded. It then intercepts specific memory operations and injects malicious PHP code into selected web application scripts.
Because the malicious code never replaces the original PHP files stored on disk, administrators examining the filesystem may believe everything is normal. Meanwhile, the Apache server continues executing the modified version that exists only in memory.
This approach represents a significant evolution in web shell techniques and demonstrates how attackers are adapting to modern detection technologies.
Why Are F5 BIG-IP Devices Being Targeted?
F5 BIG-IP Access Policy Manager is widely used by enterprises to provide secure remote access for employees, contractors, and partners. The platform offers VPN services, identity management, multi-factor authentication, and Zero Trust access controls, making it one of the most critical components in many corporate networks.
Because these appliances sit at the edge of enterprise environments, they often become attractive targets for cybercriminals. Successfully compromising an F5 BIG-IP device can provide attackers with privileged access to internal systems, user credentials, authentication tokens, and sensitive business data.
Researchers believe attackers initially exploit CVE-2025-53521, a critical unauthenticated remote code execution vulnerability. Once remote access is achieved, the Linux rootkit is installed as a second-stage payload, allowing attackers to maintain persistence without triggering traditional security alerts.
This layered attack strategy significantly increases the difficulty of incident response because the initial vulnerability may be patched while the hidden rootkit continues operating inside the compromised server.
How the Fileless PHP Web Shell Works

One of the most remarkable aspects of the Linux Rootkit F5 BIG-IP APM malware is its use of a fileless PHP web shell.
Normally, attackers upload malicious files such as shell.php or cmd.php to execute commands remotely. Security software can often detect these files during routine scans.
This rootkit takes a completely different approach.
Instead of modifying files stored on disk, it waits for Apache to load PHP. Once the PHP runtime becomes active, the malware intercepts the memory mapping process and creates a modified copy of selected PHP scripts inside RAM. The injected version contains both the original application code and a hidden web shell that accepts encrypted attacker commands.
To administrators, every PHP file on disk appears untouched. File hashes remain identical, timestamps are unchanged, and integrity monitoring reports no suspicious modifications. However, the server is actually executing malicious code from memory.
Sophos researchers identified three F5 BIG-IP APM webtop scripts that are specifically targeted by the malware:
- apm_css.php3
- full_wt.php3
- webtop_popup_css.php3
The implanted web shell communicates using specially crafted HTTP requests, decrypts incoming commands, executes them on the server, and returns results disguised as normal web traffic.
Why the Linux Rootkit F5 BIG-IP APM Is So Difficult to Detect
What makes the Linux Rootkit F5 BIG-IP APM particularly dangerous is its ability to evade many of the security tools organizations rely on every day. Traditional antivirus software, file integrity monitoring solutions, and malware scanners are primarily designed to detect malicious files stored on disk. Since this rootkit injects its malicious PHP code directly into memory, those tools often report that the system is clean even while the malware remains active.
According to Sophos researchers, the rootkit hooks into the Apache startup process before the web server begins normal operation. It waits until the PHP module, known as libphp, is loaded and then intercepts memory mapping functions. Instead of replacing the original PHP files, it creates modified copies inside memory that contain the embedded web shell.
This means administrators inspecting files such as apm_css.php3, full_wt.php3, and webtop_popup_css.php3 will only see legitimate code. Meanwhile, Apache continues executing the altered version that exists only in RAM.
This stealth technique represents a significant advancement over conventional web shells and highlights the growing use of memory-resident malware in targeted cyberattacks.
A Hidden UNIX Socket Backdoor Adds Another Layer of Persistence
The malware does not rely solely on an in-memory web shell. Sophos also discovered that it creates a hidden local UNIX socket located at:
/run/bigtlog.pipe
Unlike traditional backdoors that open TCP ports visible to network scanners, this socket communicates locally within the operating system. Because it does not expose a standard network service, many security monitoring tools fail to detect its presence.
After receiving a valid authentication token, the malware launches a Bash shell, giving attackers interactive access to the compromised appliance. From there, they can execute commands, modify files, install additional malware, or move laterally into the internal network.
This combination of a fileless web shell and a hidden local backdoor makes the malware particularly resilient and difficult to remove.
How CVE-2025-53521 Enables the Attack

Security researchers believe the rootkit is deployed only after attackers successfully exploit CVE-2025-53521, a critical unauthenticated remote code execution vulnerability affecting vulnerable F5 BIG-IP APM systems.
Because the vulnerability allows attackers to execute code without valid credentials, internet-facing devices become attractive targets. Once access is obtained, attackers install the Linux rootkit as a second-stage payload to maintain long-term control.
Although applying the latest F5 security patches blocks further exploitation of the vulnerability, organizations that were compromised before patching may still have the rootkit running in memory or installed through additional persistence mechanisms. For this reason, simply updating the software is not always enough to fully recover a compromised system.
Potential Impact on Organizations
Organizations using F5 BIG-IP APM often rely on it to protect remote access for employees, partners, and contractors. If attackers successfully compromise one of these systems, the consequences can be severe.
A successful attack could allow threat actors to maintain persistent access, steal authentication credentials, intercept VPN sessions, execute arbitrary commands, deploy additional malware, or move deeper into internal networks. Since BIG-IP appliances frequently serve as the gateway to enterprise infrastructure, compromising them can provide a pathway to sensitive applications and confidential business data.
Financial institutions, healthcare providers, government agencies, telecommunications companies, and large enterprises are among the organizations that could face the greatest risk if vulnerable appliances remain exposed.
How Security Teams Can Detect and Respond

Sophos recommends that organizations preserve volatile evidence before rebooting or modifying any suspected compromised system. Capturing process memory is particularly important because the malicious PHP code exists only in RAM and may disappear after a restart.
Security teams should also compare the PHP code stored on disk with the version loaded into Apache memory. Any differences between the two may indicate memory injection.
Other indicators include unexpected local UNIX sockets, Apache worker processes behaving abnormally, unusual HTTP 201 responses masquerading as CSS files, and child processes unexpectedly launching Bash.
Administrators should verify the integrity of Apache binaries, review SELinux configuration changes, inspect upgrade images for tampering, and follow all remediation guidance published by F5 before returning affected systems to production.
Continuous monitoring using endpoint detection and response (EDR), memory forensics, and behavioral analytics provides much stronger protection than relying solely on antivirus software.
Why This Discovery Matters for Cybersecurity
The discovery of the Linux Rootkit F5 BIG-IP APM demonstrates how cybercriminals continue evolving their techniques to bypass modern security controls.
Instead of leaving obvious malware files behind, attackers are increasingly exploiting legitimate processes and injecting malicious code directly into memory. This trend reduces the effectiveness of traditional security tools and increases the importance of advanced detection technologies capable of analyzing runtime behavior.
The incident also reinforces the need for organizations to patch critical vulnerabilities quickly, especially on internet-facing infrastructure such as VPN gateways, identity management platforms, and secure remote access appliances.
Final Thoughts
The Linux Rootkit F5 BIG-IP APM is one of the most sophisticated malware threats discovered this year. By combining memory-resident PHP web shells, runtime process hooking, hidden UNIX socket backdoors, and persistence mechanisms, attackers have demonstrated a highly advanced approach to maintaining access while avoiding detection.
Organizations running F5 BIG-IP Access Policy Manager should immediately review their exposure to CVE-2025-53521, apply the latest security updates, and perform thorough compromise assessments if exploitation is suspected. Standard antivirus scans alone are unlikely to detect this type of malware, making memory analysis and behavioral monitoring essential components of an effective incident response strategy.
As attackers continue adopting fileless techniques and AI-assisted malware development, enterprises must strengthen their security posture through proactive patch management, continuous monitoring, and comprehensive threat hunting. Staying ahead of these evolving threats is no longer optional—it is essential for protecting critical infrastructure and sensitive business data.
Internal Links
- AI News →
/artificial-intelligence/ - Tech News →
/tech-news/ - Reviews →
/reviews-buying-guides/