F5 BIG-IP APM Intrusions Hide in PHP Memory

Active intrusions are using CVE-2025-53521 against F5 BIG-IP APM appliances to install a Linux rootkit that keeps a PHP web shell in memory instead of on disk. BleepingComputer says the malware intercepts PHP file loading and injects the shell at runtime, so the appliance can be compromised without leaving the usual file artifacts. That matters because the attacker’s code rides the PHP runtime, not a dropped file. Disk-based forensics and file-hash checks can look clean even while the BIG-IP access policy layer is still under attacker control. For operators who use BIG-IP APM as the gatekeeper for virtual servers, the exposure is not just the appliance image but the control point itself. If the intrusion lives in memory, cleanup that only hunts for a bad file can miss the persistence layer entirely.

Part of the PlainSec briefing for 2026-09-08

Editions

CVEs

Sources