
Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways
A newly analyzed Linux rootkit is believed to have given attackers a way to hide shells inside recently compromised F5 BIG-IP Access Policy Management (APM) environments, without leaving the malicious PHP code on disk.
Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant, it said in a blog post, appears to be tailored specifically to BIG-IP APM webtop environments, rather than being a generic Apache or PHP attack.
The activity has been linked to the exploitation of CVE-2025-53521, an unauthenticated remote code execution (RCE) vuln...