AI Weekly Malaysia

Back to items Summaries

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

ID
22686
Status
summarized
Published
09 Sep 2026, 3:36 PM
Fetched
09 Sep 2026, 5:37 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
09 Sep 2026, 5:38 PM
Tags
Audience
developerssaas_founders

What happened

Sophos published analysis on September 7, 2026 revealing that malware targeting F5 BIG-IP APM appliances injects a PHP web shell directly into Apache's memory at runtime, modifying three specific scripts (apm_css.php3, full_wt.php3, webtop_popup_css.php3) only in-memory so disk-based file integrity checks return clean. The malware is linked to CVE-2025-53521, which F5 initially rated as denial-of-service in October 2025 but reclassified as a 9.8 CVSS remote code execution flaw on March 27, 2026 after discovering active exploitation; CISA added it to its Known Exploited Vulnerabilities catalog the same day.

Why it matters

If your organization runs F5 BIG-IP APM with an access policy on a virtual server and you relied on F5's March IOC list of modified files to confirm compromise, that check is insufficient — the web shell can exist with zero disk artifacts. The practical action is to assume file-based detection misses this strain and prioritize patching CVE-2025-53521 or verifying the appliance is not exposed, rather than trusting clean file hashes.

Discussion angle

The gap between vendor IOCs and actual detection coverage: F5 told customers in March that checking those three files was the way to spot compromise, while Sophos now shows the malware can leave those files untouched — a useful case study in why file-based indicators alone are unreliable for memory-resident threats.

Top