F5 BIG-IP malware plants fileless PHP shells in memory
Attackers are exploiting CVE-2025-53521 on internet-facing F5 BIG-IP APM to drop a Linux rootkit and a fileless PHP webshell that lives in memory. The implant answers a magic POST to targeted .php3 webtop scripts with HTTP 201 and text/css. ShadowServer counted about 795 exposed endpoints still vulnerable.

BleepingComputer reports that attackers are exploiting CVE-2025-53521 on internet-facing F5 BIG-IP Access Policy Manager devices. The path drops a Linux rootkit and a fileless PHP webshell that lives in memory, so the PHP files on disk stay clean.
This is open security reporting of active exploitation, with researcher malware analysis and F5 knowledge-base article IDs. It is not a brand-new zero-day disclosure this week.
Sophos analyzed the second-stage implant, as quoted by BleepingComputer. ESET brands the malware PoisonedRefresh. F5's campaign label is c05d5254. Vendor notes sit behind login at K000156741 (the CVE) and K000160486 (indicators for c05d5254).
The implant hooks Apache PHP loading and injects into webtop scripts such as apm_css.php3, full_wt.php3, and webtop_popup_css.php3. A magic POST decrypts, runs through eval(), and comes back as HTTP 201 with a text/css content type. There is also a password-protected local UNIX socket that can spawn Bash without opening a TCP listener.
ShadowServer counted about 795 exposed BIG-IP APM endpoints still vulnerable to CVE-2025-53521. The Hacker News lists fixed builds as 17.5.1.3, 17.1.3, 16.1.6.1, and 15.1.10.8.
F5 first framed CVE-2025-53521 as a denial-of-service issue in October 2025, then reclassified it toward unauthenticated remote code execution in March 2026. The patches are months old. Residual internet exposure is the operational story.
Internet-facing management planes this week also include SAP's CVSS 10 OVERPASS note, ConnectWise's ScreenConnect file transfer advisory, N-able N-central CVE-2026-86218, and PostgreSQL logical-decoding CVE-2026-6471.
If you still run internet-facing BIG-IP APM on builds older than 17.5.1.3, 17.1.3, 16.1.6.1, or 15.1.10.8, patch or isolate now and hunt for memory-resident PHP webtop implants that answer magic POSTs with HTTP 201 and text/css.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free