← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 10, 2026 · 11:51via CSO Online

Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways

Brief

A newly analyzed Linux rootkit is believed to have given attackers a way to hide shells inside recently compromised F5 BIG-IP Access Policy Management (APM) environments, without leaving the malicious PHP code on disk.

Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant, it said in a blog post , appears to be tailored specifically to BIG-IP APM webtop environments, rather than being a generic Apache or PHP attack.

The activity has been linked to the exploitation of CVE-2025-53521 , an unauthenticated remote code execution (RCE) vulnerability affecting BIG-IP APM when an access policy is configured on a virtual server.

Read more on CSO Online→