F5 BIG-IP APM Attackers Hide Malware in Memory to Dodge Disk Scans
Security firm Sophos has published analysis showing that malware targeting F5 BIG-IP Access Policy Manager (APM) appliances injects a PHP web shell directly into memory rather than writing it to disk. This means the malicious code loads only when Apache runs one of three legitimate PHP scripts, so a file scan comparing disk contents to known-good versions comes back clean even when the system is compromised.
The technique undermines a common defence: checking files on disk against trusted baselines. Because the web shell exists only in memory once the affected scripts run, traditional detection methods can miss it entirely. F5 had previously told customers that the presence of these three specific scripts alone does not indicate a breach, a statement the Sophos findings help explain, since the files themselves may never be altered.
F5 has linked this malicious activity to CVE-2025-53521, a flaw originally published in October 2025 as a denial-of-service issue but reclassified in March 2026 as a remote code execution vulnerability that requires no login to exploit. It carries a severity score of 9.8 out of 10, has been actively exploited, and was added to the US CISA Known Exploited Vulnerabilities catalog. The flaw affects systems where a BIG-IP APM access policy is applied to a virtual server, a configuration the UK's National Cyber Security Centre describes as common in large organisations.