{"id":9413,"date":"2026-09-10T11:51:30","date_gmt":"2026-09-10T11:51:30","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9413"},"modified":"2026-09-10T11:51:30","modified_gmt":"2026-09-10T11:51:30","slug":"stealth-rootkit-targeting-f5-big-ip-could-expose-enterprise-identity-gateways","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9413","title":{"rendered":"Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A newly analyzed Linux rootkit is believed to have given attackers a way to hide shells inside recently compromised F5 BIG-IP Access Policy Management (APM) environments, without leaving the malicious PHP code on disk.<\/p>\n<p class=\"wp-block-paragraph\">Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant, it said in a blog <a href=\"https:\/\/www.sophos.com\/en-us\/blog\/dissecting-a-php-web-server-rootkit\" target=\"_blank\" rel=\"noopener\">post<\/a>, appears to be tailored specifically to BIG-IP APM webtop environments, rather than being a generic Apache or PHP attack.<\/p>\n<p class=\"wp-block-paragraph\">The activity has been linked to the exploitation of <a href=\"https:\/\/www.csoonline.com\/article\/4152658\/5-month-old-f5-big-ip-dos-bug-becomes-critical-rce-exploited-in-the-wild.html\" target=\"_blank\" rel=\"noopener\">CVE-2025-53521<\/a>, an unauthenticated remote code execution (RCE) vulnerability affecting BIG-IP APM when an access policy is configured on a virtual server.<\/p>\n<p class=\"wp-block-paragraph\">Sophos said the sample they have now found and analyzed is a second-stage payload, while a previously identified component is responsible for infecting the Apache \u201chttpd\u201d process and deploying this payload.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>The web shell is not really a file<\/h2>\n<p class=\"wp-block-paragraph\">Sophos\u2019 analysis focused on how the malware delivers its web shell.<\/p>\n<p class=\"wp-block-paragraph\">Rather than dropping a suspicious PHP file onto the server, the implant hooks Apache\u2019s PHP-loading process and modifies the way selected PHP files are presented to the running process. Sophos found it specifically targeting three PHP files used by BIG-IP APM\u2019s webtop environment.<\/p>\n<p>These files included \u201capm_css.php3\u201d, \u201cfull_wt.php3\u201d, and \u201cwebtop_popup_css.php3.\u201d<\/p>\n<p class=\"wp-block-paragraph\">When PHP attempts to memory-map one of those files, as part of the routine PHP runtime, the rootkit intercepts the operation and creates a modified in-memory version containing the malicious web shell alongside the legitimate script. The file on disk remains unchanged.<\/p>\n<p class=\"wp-block-paragraph\">That makes the technique nearly invisible to conventional web-shell detection tools. A scan of the filesystem would show a perfectly legitimate PHP file while the Apache process is executing a modified version <a href=\"https:\/\/www.csoonline.com\/article\/643356\/fileless-attacks-surge-as-cybercriminals-evade-cloud-security-defenses.html\">in memory<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe significance here isn\u2019t just that the web shell is stealthier,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/seantmalone\/\" target=\"_blank\" rel=\"noopener\">Sean Malone<\/a>, chief information security officer at BeyondTrust. \u201cIt\u2019s that it defeats the assumption most response playbooks rest on: that the file on disk tells you what the server is running.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The malware serves a poisoned copy of three legitimate BIG-IP APM files only inside the running Apache process, so hashes match, file-integrity monitoring passes, and the box looks clean while it\u2019s owned, Malone explained.<\/p>\n<p class=\"wp-block-paragraph\">The implant also establishes a second access mechanism through a local UNIX socket, rather than opening a conventional TCP listener. After authentication, the socket can provide an interactive \u201c\/bin\/bash\u201d session, giving an attacker another way into the system while avoiding some network-based detection.<\/p>\n<p class=\"wp-block-paragraph\">Sophos said the combination of these techniques creates a web-shell capability that is harder to detect using file-centric or PHP-only monitoring.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Compromise could expose the identity gateway<\/h2>\n<p class=\"wp-block-paragraph\">The implications extend beyond the F5 appliance itself.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAn attacker with access to BIG-IP APM can intercept SSO tokens and credentials, inject policy decisions, monitor user traffic, and move laterally to downstream applications and SaaS tenants that trust the appliance,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/agnidipta\/\" target=\"_blank\" rel=\"noopener\">Agnidipta Sarkar<\/a>, chief evangelist at ColorTokens.<\/p>\n<p class=\"wp-block-paragraph\">Sarkar noted that BIG-IP APM is commonly deployed by large enterprises, financial institutions, and public-sector organizations to provide remote access and federated SSO to internal applications, APIs, and cloud services. Because the appliances sit at the network perimeter, process credentials and session tokens, and terminate <a href=\"https:\/\/www.csoonline.com\/article\/4097721\/how-cisos-can-prepare-for-the-new-era-of-short-lived-tls-certificates.html\">TLS<\/a>, they represent particularly valuable targets. <\/p>\n<p class=\"wp-block-paragraph\">For defenders, Sarkar recommended investigating systems that were vulnerable before they were patched, as applying the fix does not rule out an earlier compromise. He also recommends combining F5\u2019s indicators of compromise with memory and behavioral telemetry, since file scans alone may miss the rootkit\u2019s in-memory activity.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A newly analyzed Linux rootkit is believed to have given attackers a way to hide shells inside recently compromised F5 BIG-IP Access Policy Management (APM) environments, without leaving the malicious PHP code on disk. Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9414,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9413","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9413"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9413"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9413\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9414"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9413"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}