LmCast :: Stay tuned in

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Recorded: Sept. 8, 2026, 8:01 p.m.

Original Summarized

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

News

Featured
Latest

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Adobe fixes critical Magento zero-day exploited to backdoor servers

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

August updates trigger 0xc0000409 errors on Windows Server 2016

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Microsoft releases Windows 10 KB5122878 extended security update

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Get an intro to the CISSP exam's 8 domains for $14.97 in this deal

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityHackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

By Bill Toulas

September 8, 2026
04:08 PM
0

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.
The malware shows signs of being a second-stage payload that was likely deployed after exploiting CVE-2025-53521, a critical remote code execution (RCE) flaw that F5 Networks reclassified from a DoS problem in March.
Sophos researchers analyzed a sample and noted that, while it enables “on-demand server-side code execution” typically associated with webshells, it achieves this through “deeper Linux- and Apache-specific tradecraft.”
During the research, Sophos learned that the same malware was analyzed by ESET, who identifies it as ‘PoisonedRefresh.’
In technical analysis published this week, Sophos says that the payload was deployed by a distinct installer or propagation component that had infected the Apache /usr/sbin/httpd executable used on BIG-IP APM systems.
The malicious installer also modified SELinux configurations and achieved persistence across BIG-IP upgrade images, Sophos researchers say.
"The second-stage sample hides key operational strings with RC4, gains execution before the host application main() function is invoked by intercepting __libc_start_main, targets Apache’s PHP module by hooking the Apache Portable Runtime (APR) module loader (apr_dso_load), and injects a PHP web shell into memory."
The rootkit starts with Apache, with the second-stage implant intercepting PHP file operations and modifying them in memory to hide a web shell in legitimate scripts (e.g., apm_css.php3, full_wt.php3, and webtop_popup_css.php3).
Sophos notes that the scripts were likely targeted because they are present in BIG-IP APM webtop environments and are less likely to trigger security alerts. Additionally, the PHP files on disk remain unchanged, significantly reducing the detection surface.
The injected webshell accepts specially formatted (“magic”) requests, decrypts their contents, executes them through PHP’s eval() function, and returns an HTTP 201 response disguised as CSS content.

Rootkit injecting the web shell into a PHP script’s in-memory copySource: Sophos
Sophos highlights a protection mechanism that delays the creation of the local backdoor when Apache starts, reducing the risk of service disruption and detection.
“When the Apache process begins making routine time calls, the implant spawns and detaches the worker thread responsible for creating the local UNIX socket backdoor,” Sophos explains.
“This timing minimizes the risk of destabilizing the service and helps the implant blend into normal runtime behavior.”
The rootkit also creates a password-protected local communication socket that can launch an interactive Bash shell without opening a TCP listening port.
The socket isn’t directly exposed to the internet, so attackers would need another foothold on the device to access it; however, Sophos did not identify the component used to interact with it.

Launching Bash through the local UNIX socketSource: Sophos
The security firm shared a set of signals for malicious activity linked to the malware, which include Apache workers reading /proc/self/maps, changing libphp memory protections, creating /run/bigtlog.pipe, or launching /bin/bash.
Defenders are also advised to investigate unusual POST requests to the targeted .php3 endpoints and PHP responses combining HTTP 201 with a text/css content type.
The ShadowServer Foundation, which offers a tracker for F5 BIG-IP APM systems vulnerable to CVE-2025-53521, reports that 795 endpoints were exposed online yesterday.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
Adobe fixes critical Magento zero-day exploited to backdoor serversN-able patches max severity N-central flaw amid ongoing attacksCritical Elementor Pro flaw exploited to take over WordPress sitesHackers exploit Sangoma Switchvox flaw to deploy reverse shellsSonicWall warns of actively exploited SMA1000 zero-day flaws

Actively Exploited
Backdoor
BIG-IP APM
F5
PoisonedRefresh
RCE
Remote Code Execution
Rootkit

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Sponsor Posts

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

CTI Starter Kit + 2026 SANS CTI Survey

Unify ransomware protection and recovery for every client

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Hackers have successfully exploited vulnerabilities in F5 BIG-IP APM devices to deploy a Linux rootkit capable of establishing a fileless web shell, demonstrating sophisticated post-exploitation techniques. This malware functions as a second-stage payload, likely deployed subsequent to an initial Remote Code Execution flaw, specifically CVE-2025-53521, which F5 Networks recently reclassified from a Denial of Service issue. Research by Sophos and ESET identified the malicious sample, which they named PoisonedRefresh, analyzing how it leverages deeper Linux and Apache-specific techniques to achieve code execution within the environment.

The method employed involves modifying core system components to inject code directly into memory without writing malicious files to disk. The rootkit achieves this by targeting the Apache /usr/sbin/httpd executable used on BIG-IP APM systems. The malicious installer modified SELinux configurations and ensured persistence across subsequent BIG-IP upgrade images. Technically, the implant hooks execution flow by intercepting the Apache Portable Runtime (APR) module loader, specifically the apr_dso_load function, and also targets the __libc_start_main function to gain control before the host application's main function is invoked. This allows the payload to fully hijack the process memory.

Following initial code execution, the rootkit intercepts PHP file operations and modifies them in memory to conceal a web shell within legitimate scripts, such as apm_css.php3, full_wt.php3, and webtop_popup_css.php3. This manipulation ensures that the actual files on disk remain unchanged, which significantly reduces the surface area for traditional file-based detection. The injected webshell functions by accepting specific "magic" requests, decrypting their contents, executing them through PHP's eval() function, and returning an HTTP 201 response disguised as CSS content.

To evade immediate detection upon system startup, the rootkit incorporates a protective mechanism that delays creating the local UNIX socket backdoor until the Apache process begins routine time calls, thereby blending the implant into normal runtime behavior and minimizing service disruption risk. Furthermore, the malware establishes a password-protected local communication socket that enables an interactive Bash shell without exposing a listening port to the internet; access to this socket would require an attacker to already have another foothold on the device.

Defenders are advised to investigate specific indicators of compromise related to this activity. These signals include monitoring Apache workers for reading /proc/self/maps, changes in libphp memory protections, the creation of files like /run/bigtlog.pipe, or the execution of /bin/bash. Security personnel should also scrutinize unusual POST requests aimed at the .php3 endpoints and examine PHP responses that combine an HTTP 201 status code with a text/css content type. The ShadowServer Foundation reports that numerous F5 BIG-IP APM endpoints remain exposed, indicating ongoing risk associated with this vulnerability.