Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways
Brief
A newly analyzed Linux rootkit is believed to have given attackers a way to hide shells inside recently compromised F5 BIG-IP Access Policy Management (APM) environments, without leaving the malicious PHP code on disk.
Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant, it said in a blog post , appears to be tailored specifically to BIG-IP APM webtop environments, rather than being a generic Apache or PHP attack.
The activity has been linked to the exploitation of CVE-2025-53521 , an unauthenticated remote code execution (RCE) vulnerability affecting BIG-IP APM when an access policy is configured on a virtual server.
