INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

F5 BIG-IP APM Malware Injects a PHP Web Shell

| 2026-09-09 07:36 CRITICAL HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
The UK's National Cyber Security Center has identified BIG-IP APM as a common component in large organizations, with the patch released in October 2025 still protecting against exploitation. However, Ireland's NCSC advises investigating for compromise regardless of when the system was updated, and F5 recommends isolating the appliance and rebuilding it as new to prevent an outage. The malware also infects umount, httpd, and [IOC HIDDEN • LOGIN REQUIRED] inside BIG-IP install images, spreading through installation media. General document context suggests that F5 has linked this activity to appliances affected by CVE-2025-53521.
Technical Mitigations AI-generated
* Use a secure file system, such as NFS or CIFS, to store sensitive data on the F5 BIG-IP APM devices. This can help prevent unauthorized access and reduce the attack surface. * Implement a least privilege access policy for all users accessing the F5 BIG-IP APM devices. This means that only necessary personnel should have access to the device's configuration files or other critical data. * Regularly update and patch the Apache web server program on the F5 BIG-IP APM devices to ensure that any known vulnerabilities are addressed before they can be exploited by attackers. * Use a secure boot process for the F5 BIG-IP APM devices, such as UEFI Secure Boot or BIOS Secure Boot. This can help prevent malware from being loaded into memory without proper authorization. * Implement a network segmentation strategy to isolate the F5 BIG-IP APM devices from other networks and systems. This can help reduce the attack surface and make it more difficult for attackers to spread their malware.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

bi•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
de•••••.com
ww•••••.com
ad•••••.com
tr•••••.io
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
26bd5b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
17.5.•••.•••
15.1.•••.•••
16.1.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters CVE-2025-53521CVE-2025-53521
Target & Sectors
FIVE_EYES FIVE_EYES NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2016 August
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into the memory of Windows Server 2016.
infrastructure Windows
tactic T1584.004 - Server
infrastructure 2016 Windows Server
‎October 2025
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into the memory of an appliance in Ireland, evading disk scans.
target_region Ireland
organisation NCSC
‎October 15, 2025
Threat actors used F5 BIG-IP APM malware to inject a PHP web shell into memory.
‎March 27, 2026
The patch was fixed in 17.1.3, and the UK's National Cyber Security Center calls BIG-IP APM a common component, especially in large organizations.
tactic Remote Code Execution
organisation F5
organisation National Cyber Security Center
infrastructure 17.5.0
infrastructure 17.5.1
infrastructure 17.1.0
infrastructure 17.1.2
infrastructure 17.1.3
infrastructure 16.1.0
infrastructure 16.1.6
infrastructure 15.1.0
infrastructure 15.1.10
organisation /run/bigtlog.pipe
organisation /usr/bin
organisation CSS
organisation APM
organisation ESET
organisation PoisonedRefresh
organisation SELinux
organisation iControl
‎March 30
Threat actors used a F5 BIG-IP APM exploit to inject a PHP web shell into the memory of a vulnerable system.
attribution CISA
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎March 31
Threat actors used a F5 BIG-IP APM exploit to inject a PHP web shell into the targeted system's memory.
target_region Ireland
‎September 7
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into memory instead of in a file on disk.
tactic T1588.001 - Malware
organisation PHP
organisation Sophos
‎2026/09/07
Threat actors used a known vulnerability in F5 BIG-IP APM systems to inject a PHP web shell into memory and evade disk scans.
vulnerability CVE-2025-53521
organisation The ShadowServer Foundation
infrastructure 795 endpoints
‎September 8, 2026
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into the memory of targeted devices.
infrastructure Linux
organisation ThreatLocker
‎2003 - 2026
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into the memory of targeted systems.
organisation Social & Feeds
‎2026/09/09
The malware used by threat actors to target F5 BIG-IP APM systems injects a PHP web shell into memory, evading disk scans.
organisation CVE-2025
organisation CVE-2025-53521
organisation F5 Networks
organisation DoS
organisation WordPress
organisation SonicWall
organisation CSS
organisation POST
organisation BIG-IP APM
organisation PHP
infrastructure Linux
organisation Sophos
organisation ESET
organisation APM
organisation SELinux
organisation BIG-IP
organisation Webinar
organisation infosec news
organisation Hackers
infrastructure Microsoft 365
organisation BigBear Microsoft 365
organisation MFA
victims 258 organizations
infrastructure Windows
organisation Stack Protection
organisation Windows Registry
organisation the Windows Registry
organisation EU CRA
organisation Magento
organisation Adobe
threat_actor ShinyHunters
organisation DMV
organisation DoppelCart
organisation IP
organisation safely.jpg
organisation APR
organisation TCP
organisation The Blue Report 2026
organisation CTI
organisation Upcoming Webinar
organisation ClickFix
organisation Freestar.com
‎September 2026
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into memory.
general_metric 2 Video
organisation Microsoft
general_metric 966 flaws
Tactical Metrics
Metrics
infrastructure
‎17.5.0
Software Version
Metrics
infrastructure
‎17.5.1
Software Version
Metrics
infrastructure
‎17.1.0
Software Version
Metrics
infrastructure
‎17.1.2
Software Version
Metrics
infrastructure
‎17.1.3
Software Version
Metrics
infrastructure
‎16.1.0
Software Version
Metrics
infrastructure
‎16.1.6
Software Version
Metrics
infrastructure
‎15.1.0
Software Version
Metrics
infrastructure
‎15.1.10
Software Version
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
victims
258
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
2,016
Windows Server
Metrics
infrastructure
795
Endpoints
Intelligence Sources