importantSYS.SOURCE: The Hacker News• 2026-09-09T13:06:49+05:30
F5 BIG-IP APM Malware Evades Disk Scans by Injecting PHP Web Shell into Memory
A newly discovered malware targets F5 BIG-IP APM appliances by injecting a PHP web shell into memory, bypassing traditional disk-based detection methods. The exploit leverages CVE-2025-53521, a remote code execution vulnerability, and researchers highlight behavioral indicators for detection.
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.
When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are
*** END OF TRANSMISSION ***