Overview
Sophos has analyzed malware linked to F5 BIG‑IP Access Policy Manager (APM) break‑ins that hides a PHP web shell in memory rather than on disk. This stealth technique means traditional file‑based scans may return clean results even though the appliance is compromised.
How the Malware Works
- Memory injection: The malware hooks into Apache’s runtime and injects a web shell into memory when PHP scripts are loaded.
- Targeted scripts:
apm_css.php3,full_wt.php3, andwebtop_popup_css.php3. - Execution flow:
- Infects Apache (
/usr/sbin/httpd) with malicious code. - Hooks
apr_dso_loaduntil PHP loads. - Alters memory permissions around
libphp. - Inserts the web shell into mapped memory pages.
- Infects Apache (
- Stealth response: Replies with HTTP 201 and CSS content type, disguising malicious traffic as stylesheet requests.
Exploited Vulnerability
- Linked to CVE‑2025‑53521.
- Initially classified as denial‑of‑service in October 2025, later reclassified as remote code execution in March 2026.
- Rated CVSS 9.8 (v3.1) and 9.3 (v4.0).
- Exploitation requires no login if an APM access policy is set on a virtual server.
- Patch releases:
- 17.5.0–17.5.1 → fixed in 17.5.1.3
- 17.1.0–17.1.2 → fixed in 17.1.3
- 16.1.0–16.1.6 → fixed in 16.1.6.1
- 15.1.0–15.1.10 → fixed in 15.1.10.8
Indicators of Compromise (IoCs)
- Files:
/run/bigtlog.pipe,/run/bigstart.ltm, modified/usr/bin/umountor/usr/sbin/httpd. - Logs: SELinux disabled, base64 data written into files, bash commands via iControl REST.
- Traffic: HTTP 201 responses with CSS content type.
- Behavior: Apache worker reading
/proc/self/maps, altering memory permissions, binding sockets under/run. - Hash:
26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9.
Defensive Guidance
- Run sys‑eicheck to detect integrity failures in
umountorhttpd. - Collect qkview reports and submit to F5 for compromise checks.
- Compare modules in memory against disk copies.
- Isolate and rebuild appliances if full investigation is not possible.
- Monitor behavioral signals: unexpected Apache memory changes, socket bindings, or bash execution.
Expert in the Cloud Insight
This campaign highlights the shift from disk‑based persistence to memory‑resident malware. By injecting web shells directly into PHP runtime, attackers bypass traditional detection and create stealthy footholds in critical infrastructure. The lesson is clear: defenders must expand incident response playbooks to include memory analysis, runtime integrity checks, and behavioral monitoring.
Leave a Reply