Download Privacy Needle App

Type to search

Cybersecurity

Stealthy Rootkit Targets F5 BIG-IP to Intercept Identity Tokens

Share

A new Linux rootkit targeting F5 BIG-IP Access Policy Management (APM) environments can hide malicious web shells within a system’s memory, allowing attackers to bypass conventional file-based security tools.

Sophos researchers discovered the malware, which uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant appears tailored specifically to BIG-IP APM webtop environments rather than being a generic Apache or PHP attack.

In-Memory Stealth Bypasses File Scans

Rather than dropping a suspicious PHP file onto the server, the rootkit hooks the Apache PHP-loading process and modifies how selected files are presented to the running process. The implant specifically targets three legitimate PHP files used by the BIG-IP APM webtop environment: apm_css.php3, full_wt.php3, and webtop_popup_css.php3.

When PHP attempts to memory-map one of these files as part of its routine runtime, the rootkit intercepts the operation and creates a modified in-memory version containing the malicious web shell alongside the legitimate script. Because the file on disk remains unchanged, file-integrity monitoring and standard filesystem scans will show the system as clean even while it is compromised.

Sean Malone, chief information security officer at BeyondTrust, noted that this technique defeats a fundamental assumption used by many incident response playbooks: that the file on disk accurately represents what the server is running.

Identity and Credential Risks

The malware also establishes a secondary access mechanism through a local UNIX socket instead of a conventional TCP listener. Once authenticated, this socket can provide an interactive /bin/bash session, providing attackers with a way to access the system while avoiding network-based detection.

The implications of a compromise extend beyond the F5 appliance to the broader enterprise identity infrastructure. Agnidipta Sarkar, chief evangelist at ColorTokens, warned that an attacker with access to BIG-IP APM can intercept single sign-on (SSO) tokens and credentials, inject policy decisions, and move laterally to downstream applications or SaaS tenants that trust the appliance.

Vulnerability and Mitigation

The activity has been linked to the exploitation of CVE-2025-53521, an unauthenticated remote code execution (RCE) vulnerability affecting BIG-IP APM when an access policy is configured on a virtual server.

Security experts recommend that defenders investigate systems that were vulnerable prior to patching, as applying the fix does not rule out an earlier compromise. Organisations should combine F5’s indicators of compromise with memory and behavioural telemetry, as file scans alone may fail to detect the rootkit’s in-memory activity.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.