Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
F5 BIG-IP APM Malware Hides PHP Web Shell in Memory

F5 BIG-IP APM Malware Hides PHP Web Shell in Memory

Posted on September 9, 2026 By CWS

Malware Overview

Recent findings by Sophos have identified a sophisticated malware targeting F5 BIG-IP Access Policy Manager (APM) appliances. This malware operates by embedding a PHP web shell directly into memory, bypassing traditional disk-based detection methods. This tactic allows the malware to evade standard security checks, as highlighted in Sophos’s analysis dated September 7.

In-Memory Web Shell Execution

The malware leverages Apache’s process of loading PHP scripts by injecting the web shell into the memory, rather than storing it on disk. This method makes detecting the compromise challenging, as file-based scans return clean results. The compromised scripts include apm_css.php3, full_wt.php3, and webtop_popup_css.php3, which were previously identified by F5 in March as potential indicators of compromise.

Implications of the Malware

F5 initially identified the related activity as c05d5254, linking it to a vulnerability tracked as CVE-2025-53521. This flaw, originally classified as a denial-of-service issue, was later reclassified as a remote code execution vulnerability, with a critical CVSS score of 9.8. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) quickly added the vulnerability to its Known Exploited Vulnerabilities catalog, emphasizing its severity.

Organizations utilizing BIG-IP APM, particularly within large infrastructures, are significantly affected due to the widespread use of this component. The UK’s National Cyber Security Center has underscored the commonality of BIG-IP APM in such environments, necessitating vigilant monitoring and patching practices.

Technical Details and Defense Strategies

The malware’s final payload is deployed after exploiting an installation program that infects Apache’s HTTP daemon. This approach involves modifying memory permissions to introduce malicious elements before restoring original access rights, ensuring stealth operation. The web shell executes commands by interpreting specific HTTP requests, disguising its activity as legitimate traffic.

Defenders are advised to investigate behavioral indicators, such as abnormal Apache process activities and discrepancies in binary file attributes, to identify potential compromises. Specific anomalies, like HTTP status 201 responses with CSS content types, may indicate malicious activity.

Recommendations and Future Outlook

Security experts recommend conducting thorough integrity checks using tools like F5’s sys-eicheck and submitting qkview reports for analysis by F5. Organizations should also consider isolating and rebuilding compromised appliances to ensure a clean environment. The National Cyber Security Centers of Ireland and the UK stress the importance of these measures, even in the absence of direct evidence of exploitation.

While the exact timeline of exploitation remains unclear, proactive monitoring and incident response protocols are crucial. The persistence of malware components through system upgrades poses additional challenges, necessitating ongoing vigilance. As investigations continue, identifying the responsible attackers and understanding the full scope of the threat are priorities for cybersecurity experts.

The Hacker News Tags:APM, CISA, CVE-2025-53521, Cybersecurity, F5 BIG-IP, Malware, National Cyber Security Center, PHP web shell, remote code execution, security breach, Sophos

Post navigation

Previous Post: Windows Defender Vulnerability: New Flaw Discovered
Next Post: Critical ICS Vulnerabilities Patched by Schneider and Siemens

Related Posts

Emerging Cyber Threats and Security Flaws Reviewed Emerging Cyber Threats and Security Flaws Reviewed The Hacker News
ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts The Hacker News
Ghostwriter Intensifies Phishing Attacks on Ukraine Ghostwriter Intensifies Phishing Attacks on Ukraine The Hacker News
Apache ActiveMQ Vulnerability Exploited, Urgent Fix Advised Apache ActiveMQ Vulnerability Exploited, Urgent Fix Advised The Hacker News
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware The Hacker News
CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Use Google Sheets in Crypto Wallet Attacks
  • Advanced Phishing Tactics Exploit Victim Browsers
  • DeepSeek Harness Flaw Allows AI Sandbox Bypass
  • New Windows BitLocker Flaw Allows Remote Code Execution
  • Critical ICS Vulnerabilities Patched by Schneider and Siemens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Use Google Sheets in Crypto Wallet Attacks
  • Advanced Phishing Tactics Exploit Victim Browsers
  • DeepSeek Harness Flaw Allows AI Sandbox Bypass
  • New Windows BitLocker Flaw Allows Remote Code Execution
  • Critical ICS Vulnerabilities Patched by Schneider and Siemens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark