INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
F5 BIG-IP APM Malware Injects a PHP Web Shell
| 2026-09-09 07:36 CRITICAL HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
The UK's National Cyber Security Center has identified BIG-IP APM as a common component in large organizations, with the patch released in October 2025 still protecting against exploitation. However, Ireland's NCSC advises investigating for compromise regardless of when the system was updated, and F5 recommends isolating the appliance and rebuilding it as new to prevent an outage. The malware also infects umount, httpd, and [IOC HIDDEN • LOGIN REQUIRED] inside BIG-IP install images, spreading through installation media. General document context suggests that F5 has linked this activity to appliances affected by CVE-2025-53521.
Technical Mitigations AI-generated
* Use a secure file system, such as NFS or CIFS, to store sensitive data on the F5 BIG-IP APM devices. This can help prevent unauthorized access and reduce the attack surface.
* Implement a least privilege access policy for all users accessing the F5 BIG-IP APM devices. This means that only necessary personnel should have access to the device's configuration files or other critical data.
* Regularly update and patch the Apache web server program on the F5 BIG-IP APM devices to ensure that any known vulnerabilities are addressed before they can be exploited by attackers.
* Use a secure boot process for the F5 BIG-IP APM devices, such as UEFI Secure Boot or BIOS Secure Boot. This can help prevent malware from being loaded into memory without proper authorization.
* Implement a network segmentation strategy to isolate the F5 BIG-IP APM devices from other networks and systems. This can help reduce the attack surface and make it more difficult for attackers to spread their malware.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
bi•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
de•••••.com
ww•••••.com
ad•••••.com
tr•••••.io
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
26bd5b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
17.5.•••.•••
15.1.•••.•••
16.1.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
CVE-2025-53521CVE-2025-53521
Target & Sectors
FIVE_EYES
FIVE_EYES
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
2016 August
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into the memory of Windows Server 2016.
Click on any entity below to view its context and source!
infrastructure
Windows
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
tactic
T1584.004 - Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
infrastructure
2016 Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
October 2025
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into the memory of an appliance in Ireland, evading disk scans.
Click on any entity below to view its context and source!
target_region
Ireland
Ireland's NCSC said no timeline for exploitation is available, and that it expects some exploitation was or could have been happening before the flaw and its fix were first published in October 2025.
organisation
NCSC
Ireland's NCSC said no timeline for exploitation is available, and that it expects some exploitation was or could have been happening before the flaw and its fix were first published in October 2025.
October 15, 2025
Threat actors used F5 BIG-IP APM malware to inject a PHP web shell into memory.
March 27, 2026
The patch was fixed in 17.1.3, and the UK's National Cyber Security Center calls BIG-IP APM a common component, especially in large organizations.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
On March 27, 2026, F5 said new information had led it to
reclassify the flaw as remote code execution
, and that it had been exploited.
organisation
F5
On March 27, 2026, F5 said new information had led it to
reclassify the flaw as remote code execution
, and that it had been exploited.
organisation
National Cyber Security Center
The UK's National Cyber Security Center calls BIG-IP APM a common component, especially in large organizations.
infrastructure
17.5.0
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
infrastructure
17.5.1
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
infrastructure
17.1.0
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
infrastructure
17.1.2
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
infrastructure
17.1.3
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
infrastructure
16.1.0
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
infrastructure
16.1.6
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
infrastructure
15.1.0
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
infrastructure
15.1.10
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
organisation
/run/bigtlog.pipe
The malware also opens a local socket at /run/bigtlog.pipe.
organisation
/usr/bin
bigstart.ltm present
Binary
: hash, size or timestamp mismatch on /usr/bin/umount or /usr/sbin/httpd against a known good copy.
organisation
CSS
It replies with HTTP status 201 and a CSS content type, so the exchange looks like a request for a stylesheet.
organisation
APM
The flaw applies where a BIG-IP APM access policy is set on a virtual server.
organisation
ESET
ESET, which
analyzed related samples in April
and named the malware PoisonedRefresh, said the installer is meant to be run as root and turns off SELinux.
organisation
PoisonedRefresh
ESET, which
analyzed related samples in April
and named the malware PoisonedRefresh, said the installer is meant to be run as root and turns off SELinux.
organisation
SELinux
ESET, which
analyzed related samples in April
and named the malware PoisonedRefresh, said the installer is meant to be run as root and turns off SELinux.
organisation
iControl
F5 notes that sizes and timestamps differ between releases and engineering hotfixes
Tool
: sys-eicheck failing because one of those two files has changed
Log
: an entry in /var/log/restjavad-audit showing a local user reaching the iControl REST API from localhost
Log
: an entry in /var/log/auditd showing SELinux being switched off by the same route
Log
: an entry in /var/log/audit showing a bash command run through iControl REST.
March 30
Threat actors used a F5 BIG-IP APM exploit to inject a PHP web shell into the memory of a vulnerable system.
Click on any entity below to view its context and source!
attribution
CISA
CISA added it to its Known Exploited Vulnerabilities catalog the same day, giving U.S. federal civilian agencies until March 30 to act.
attribution
Known Exploited
CISA added it to its Known Exploited Vulnerabilities catalog the same day, giving U.S. federal civilian agencies until March 30 to act.
tactic
T1588.006 - Vulnerabilities
CISA added it to its Known Exploited Vulnerabilities catalog the same day, giving U.S. federal civilian agencies until March 30 to act.
March 31
Threat actors used a F5 BIG-IP APM exploit to inject a PHP web shell into the targeted system's memory.
Click on any entity below to view its context and source!
target_region
Ireland
Ireland's National Cyber Security Center said in a
March 31 advisory
that the patch released in October is still valid and will protect against exploitation.
September 7
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into memory instead of in a file on disk.
Click on any entity below to view its context and source!
tactic
T1588.001 - Malware
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.
organisation
PHP
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.
organisation
Sophos
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.
2026/09/07
Threat actors used a known vulnerability in F5 BIG-IP APM systems to inject a PHP web shell into memory and evade disk scans.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-53521
The ShadowServer Foundation, which offers a tracker for F5 BIG-IP APM systems vulnerable to CVE-2025-53521, reports that 795 endpoints were exposed online yesterday.
!
organisation
The ShadowServer Foundation
The ShadowServer Foundation, which offers a tracker for F5 BIG-IP APM systems vulnerable to CVE-2025-53521, reports that 795 endpoints were exposed online yesterday.
!
infrastructure
795 endpoints
The ShadowServer Foundation, which offers a tracker for F5 BIG-IP APM systems vulnerable to CVE-2025-53521, reports that 795 endpoints were exposed online yesterday.
!
September 8, 2026
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into the memory of targeted devices.
Click on any entity below to view its context and source!
infrastructure
Linux
[Image 34: ThreatLocker](
* Home
* News
* Security
* Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
# Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
By
###### Bill Toulas
* September 8, 2026
* 04:08
organisation
ThreatLocker
[Image 34: ThreatLocker](
* Home
* News
* Security
* Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
# Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
By
###### Bill Toulas
* September 8, 2026
* 04:08
2003 - 2026
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into the memory of targeted systems.
Click on any entity below to view its context and source!
organisation
Social & Feeds
* Advertising
* Write for BleepingComputer
* Social & Feeds
* Changelog
Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure
Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved
[]( "Back to Top")
2026/09/09
The malware used by threat actors to target F5 BIG-IP APM systems injects a PHP web shell into memory, evading disk scans.
Click on any entity below to view its context and source!
organisation
CVE-2025
F5 has linked the c05d5254 activity to appliances affected by
CVE-2025-53521
, Sophos said.
organisation
CVE-2025-53521
The malware shows signs of being a second-stage payload that was likely deployed after exploiting CVE-2025-53521, a critical remote code execution (RCE) flaw that F5 Networks reclassified from a DoS problem in March.
organisation
F5 Networks
The malware shows signs of being a second-stage payload that was likely deployed after exploiting CVE-2025-53521, a critical remote code execution (RCE) flaw that F5 Networks reclassified from a DoS problem in March.
organisation
DoS
The malware shows signs of being a second-stage payload that was likely deployed after exploiting CVE-2025-53521, a critical remote code execution (RCE) flaw that F5 Networks reclassified from a DoS problem in March.
organisation
WordPress
Adobe fixes critical Magento zero-day exploited to backdoor servers
N-able patches max severity N-central flaw amid ongoing attacks
Critical Elementor Pro flaw exploited to take over WordPress sites
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
SonicWall warns of actively exploited SMA1000 zero-day flaws
* Actively Exploited
* Backdoor
* BIG-IP APM
* F5
* PoisonedRefresh
* RCE
* Remote Code Execution
*
organisation
SonicWall
Adobe fixes critical Magento zero-day exploited to backdoor servers
N-able patches max severity N-central flaw amid ongoing attacks
Critical Elementor Pro flaw exploited to take over WordPress sites
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
SonicWall warns of actively exploited SMA1000 zero-day flaws
* Actively Exploited
* Backdoor
* BIG-IP APM
* F5
* PoisonedRefresh
* RCE
* Remote Code Execution
*
organisation
CSS
The injected webshell accepts specially formatted (“magic”) requests, decrypts their contents, executes them through PHP’s _eval()_ function, and returns an HTTP 201 response disguised as CSS content.
!
organisation
POST
Defenders are also advised to investigate unusual POST requests to the targeted .php3 endpoints and PHP responses combining HTTP 201 with a text/css content type.
organisation
BIG-IP APM
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans.
In technical analysis published this week, Sophos says that the payload was deployed by a distinct installer or propagation component that had infected the Apache _/usr/sbin/httpd_ executable used on BIG-IP APM systems.
organisation
PHP
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.
infrastructure
Linux
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.
Sophos researchers analyzed a sample and noted that, while it enables “on-demand server-side code execution” typically associated with webshells, it achieves this through “deeper Linux- and Apache-specific tradecraft.”
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
During the research, Sophos learned that the same malware was analyzed by ESET, who identifies it as ‘PoisonedRefresh.’
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit.
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
organisation
Sophos
Sophos researchers analyzed a sample and noted that, while it enables “on-demand server-side code execution” typically associated with webshells, it achieves this through “deeper Linux- and Apache-specific tradecraft.”
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
During the research, Sophos learned that the same malware was analyzed by ESET, who identifies it as ‘PoisonedRefresh.’
organisation
ESET
Sophos researchers analyzed a sample and noted that, while it enables “on-demand server-side code execution” typically associated with webshells, it achieves this through “deeper Linux- and Apache-specific tradecraft.”
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
During the research, Sophos learned that the same malware was analyzed by ESET, who identifies it as ‘PoisonedRefresh.’
organisation
APM
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit.
organisation
SELinux
The malicious installer also modified SELinux configurations and achieved persistence across BIG-IP upgrade images, Sophos researchers say.
organisation
BIG-IP
The malicious installer also modified SELinux configurations and achieved persistence across BIG-IP upgrade images, Sophos researchers say.
organisation
Webinar
[Image 49: Webinar](
##### Follow us:
*
organisation
infosec news
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
organisation
Hackers
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
infrastructure
Microsoft 365
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
BigBear Microsoft 365
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
MFA
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
victims
258 organizations
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
infrastructure
Windows
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
organisation
Stack Protection
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
organisation
Windows Registry
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
organisation
the Windows Registry
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
organisation
EU CRA
Check your EU CRA readiness in 5 questions.
organisation
Magento
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
organisation
Adobe
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
threat_actor
ShinyHunters
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
DMV
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
DoppelCart
[Image 7: DoppelCart fraud network uses 119,000 fake shops to steal credit cards DoppelCart fraud network uses 119,000 fake shops to steal credit cards](
* !
organisation
IP
[Image 31: How to change IP address.jpg) How to change IP address](
* !
organisation
safely.jpg
Access the dark web safely.jpg)
organisation
APR
"The second-stage sample hides key operational strings with RC4, gains execution before the host application main() function is invoked by intercepting __libc_start_main, targets Apache’s PHP module by hooking the Apache Portable Runtime (APR) module loader (apr_dso_load), and injects a PHP web shell into memory.
organisation
TCP
The rootkit also creates a password-protected local communication socket that can launch an interactive Bash shell without opening a TCP listening port.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
CTI
[Image 46: CTI Starter Kit + 2026 SANS CTI Survey CTI Starter Kit + 2026 SANS CTI Survey](
* !
organisation
Upcoming Webinar
[Image 40: ThreatLocker](
Upcoming Webinar
!
organisation
ClickFix
Blockchain Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain](
S ponsor Posts
* !
organisation
Freestar.com
Image 51!Image 52!Image 53!Image 54!Image 55!Image 56!Image 57!Image 58!Image 59!Image 60!Image 61!Image 62
Freestar.com
!
September 2026
Threat actors used a F5 BIG-IP APM malware to inject a PHP web shell into memory.
Click on any entity below to view its context and source!
general_metric
2 Video
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
organisation
Microsoft
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
966 flaws
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
Tactical Metrics
Metrics
infrastructure
17.5.0
Software Version
Click for context!
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
Metrics
infrastructure
17.5.1
Software Version
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
Metrics
infrastructure
17.1.0
Software Version
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
Metrics
infrastructure
17.1.2
Software Version
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
Metrics
infrastructure
17.1.3
Software Version
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
Metrics
infrastructure
16.1.0
Software Version
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
Metrics
infrastructure
16.1.6
Software Version
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
Metrics
infrastructure
15.1.0
Software Version
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
Metrics
infrastructure
15.1.10
Software Version
Versions known to be vulnerable
Fixed in
17.5.0 - 17.5.1
17.5.1.3
17.1.0 - 17.1.2
17.1.3
16.1.0 - 16.1.6
16.1.6.1
15.1.0 - 15.1.10
15.1.10.8
The patch that fixes this is nearly a year old.
Metrics
infrastructure
Linux
Affected Product
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit.
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
[Image 34: ThreatLocker](
* Home
* News
* Security
* Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
# Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
By
###### Bill Toulas
* September 8, 2026
* 04:08
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.
Sophos researchers analyzed a sample and noted that, while it enables “on-demand server-side code execution” typically associated with webshells, it achieves this through “deeper Linux- and Apache-specific tradecraft.”
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
During the research, Sophos learned that the same malware was analyzed by ESET, who identifies it as ‘PoisonedRefresh.’
Metrics
infrastructure
Microsoft 365
Affected Product
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
victims
258
Organizations
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
infrastructure
Windows
Affected Product
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
Metrics
infrastructure
2,016
Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
Metrics
infrastructure
795
Endpoints
The ShadowServer Foundation, which offers a tracker for F5 BIG-IP APM systems vulnerable to CVE-2025-53521, reports that 795 endpoints were exposed online yesterday.
!
Intelligence Sources
The Hacker News
2026-09-09
BleepingComputer
2026-09-08
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-10T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
48x
organisation
Identified Entity
National Cyber Security Center
entity
11x
timeline
Temporal Reference
March 31
date
9x
infrastructure
Software Version
17.5.0
version
8x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
6x
general metric
Video
1
video
4x
tactic
Cyber Operation Type
Remote Code Execution
tactic
3x
target region
Target Country
United Kingdom
country
3x
infrastructure
Affected Product
Linux
software
2x
vulnerability
CVSS Score
3
score
2x
attribution
Attributing Entity
CISA
authority
2x
general metric
Windows
11
windows
Contextual Telemetry
Context Block
16 METRICS
industry
Targeted Sector
Media
sector
vulnerability
Exploited CVE
CVE-2025-53521
cve
general metric
Responses
201
responses
general metric
Microsoft
365
microsoft
victims
Organizations
258
organizations
infrastructure
Windows Server
2,016
windows server
infrastructure
Endpoints
795
endpoints
general metric
Flaws
966
flaws
threat actor
APT Group
ShinyHunters
actor
general metric
Fake Shops
119,000
fake shops
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Hacked Sites
5,400
hacked sites
general metric
Freestar.Com
62
freestar.com
general metric
Pm
0
pm
general metric
%
37
%
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.