thehackernews.com 9 Sept 2026, 07:36 UTC

F5 BIG-IP Flaw Hid In-Memory Web Shells from Disk Scans

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

SOPHOS has analysed malware linked to intrusions into F5 BIG-IP Access Policy Manager appliances, which hides a PHP web shell in memory rather than on disk. The shell is injected when Apache loads any of three APM webtop PHP scripts: apm_css.php3, full_wt.php3 and webtop_popup_css.php3. The code is inserted into the in‑memory copy of the script, so a disk scan may not detect it.

The shell processes HTTP requests, looks for a short marker, decrypts and executes payloads, and returns HTTP 201 with a CSS content type to disguise its activity. There is also a local inter‑process channel via /run/bigtlog[.]pipe that may connect to /bin/bash, potentially giving an interactive shell without opening a network port. The analysis notes that these shells can operate entirely in memory, even if a file on disk remains unchanged, complicating traditional file‑based detections.

F5 ties the activity to CVE-2025-53521, a remote code execution flaw affecting BIG-IP BIG-IP APM when configured on a virtual server; the vulnerability was first published in October 2025 and reclassified as RCE in March 2026, with high CVSS scores. CISA added it to the Known Exploited Vulnerabilities catalog the same day, prompting swift action for U.S. federal agencies.

Defensive guidance from UK and Irish CISA affiliates urges coordinated response. The vulnerability affects multiple Big‑IP APM releases, with fixes in versions 17.5.0–17.5.1 (patched as 17.5.1[.]3), 17.1.0–17.1.2 (patch 17.1.3), 16.1.0–16.1.6 (16.1.6[.]1), and 15.1.0–15.1.10 (15.1.10[.]8). Patch application does not guarantee removal of any in‑memory compromise already present; investigators recommend running F5’s sys-eicheck integrity tool, collecting a qkview, and comparing in‑memory modules with disk copies.

If full forensics aren’t possible, isolation and rebuild of the appliance may be necessary. Analysts should look for signs including the local /run/bigtlog[.]pipe, memory‑mapped libphp manipulation, HTTP 201 responses with a CSS content type, and the presence or altered state of the three cited PHP scripts; additional indicators include file and log anomalies and specific SHA‑256 hashes. The Sophos and ESET analyses emphasise that the intrusion can span both disk and memory stages, and attribution to a named attacker remains unconfirmed.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline