Researchers Uncover Advanced Linux Rootkit Hiding Inside BIG-IP Web Servers
Security researchers at Sophos X-Ops have analysed a highly advanced piece of Linux malware found on systems running F5 BIG-IP Access Policy Management (APM) with Apache and PHP components. The malware uses sophisticated techniques such as custom code loading, function hooking, and runtime patching to hide a web shell that gives attackers ongoing remote access to affected servers, all without leaving traces on disk.
According to Sophos, this implant appears to be a second stage payload, deployed by an earlier installer component that infects the Apache web server binary, persists across BIG-IP software upgrades, and even modifies security settings on the host. F5 has linked related attack activity to CVE-2025-53521, a serious vulnerability in BIG-IP APM that allows attackers to run code remotely without authentication when certain access policies are configured. The malware hooks deep into how Apache loads its PHP module, injecting a hidden web shell directly into memory so that only the compromised process can see the malicious code.
Businesses running F5 BIG-IP APM environments with Apache and PHP should treat this as a high-priority risk. F5 has published specific remediation and compromise-assessment guidance for CVE-2025-53521, and organisations should follow that guidance rather than relying only on generic server hardening.
This summary is based on early findings, further technical detail from Sophos is expected to follow.