Cybersecurity Research

Researchers Uncover Advanced Linux Rootkit Hiding Inside BIG-IP Web Servers

Sophos · 7 Sept 2026
Key Takeaway If your business uses F5 BIG-IP APM with Apache and PHP, check your version against CVE-2025-53521 and follow F5's official remediation guidance immediately rather than assuming standard patching is enough.

Security researchers at Sophos X-Ops have analysed a highly advanced piece of Linux malware found on systems running F5 BIG-IP Access Policy Management (APM) with Apache and PHP components. The malware uses sophisticated techniques such as custom code loading, function hooking, and runtime patching to hide a web shell that gives attackers ongoing remote access to affected servers, all without leaving traces on disk.

According to Sophos, this implant appears to be a second stage payload, deployed by an earlier installer component that infects the Apache web server binary, persists across BIG-IP software upgrades, and even modifies security settings on the host. F5 has linked related attack activity to CVE-2025-53521, a serious vulnerability in BIG-IP APM that allows attackers to run code remotely without authentication when certain access policies are configured. The malware hooks deep into how Apache loads its PHP module, injecting a hidden web shell directly into memory so that only the compromised process can see the malicious code.

Businesses running F5 BIG-IP APM environments with Apache and PHP should treat this as a high-priority risk. F5 has published specific remediation and compromise-assessment guidance for CVE-2025-53521, and organisations should follow that guidance rather than relying only on generic server hardening.

This summary is based on early findings, further technical detail from Sophos is expected to follow.

BIG-IP Linux rootkit web shell CVE-2025-53521 Sophos

Summarised by CISO AI from Sophos. We link back to every original so you can read it yourself.