F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
- ID
- 22686
- Status
- summarized
- Published
- 09 Sep 2026, 3:36 PM
- Fetched
- 09 Sep 2026, 5:37 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 09 Sep 2026, 5:38 PM
- Tags
- Audience
- developerssaas_founders
What happened
Sophos published analysis on September 7, 2026 revealing that malware targeting F5 BIG-IP APM appliances injects a PHP web shell directly into Apache's memory at runtime, modifying three specific scripts (apm_css.php3, full_wt.php3, webtop_popup_css.php3) only in-memory so disk-based file integrity checks return clean. The malware is linked to CVE-2025-53521, which F5 initially rated as denial-of-service in October 2025 but reclassified as a 9.8 CVSS remote code execution flaw on March 27, 2026 after discovering active exploitation; CISA added it to its Known Exploited Vulnerabilities catalog the same day.
Why it matters
If your organization runs F5 BIG-IP APM with an access policy on a virtual server and you relied on F5's March IOC list of modified files to confirm compromise, that check is insufficient — the web shell can exist with zero disk artifacts. The practical action is to assume file-based detection misses this strain and prioritize patching CVE-2025-53521 or verifying the appliance is not exposed, rather than trusting clean file hashes.
Discussion angle
The gap between vendor IOCs and actual detection coverage: F5 told customers in March that checking those three files was the way to spot compromise, while Sophos now shows the malware can leave those files untouched — a useful case study in why file-based indicators alone are unreliable for memory-resident threats.