Hackers deployed a Linux rootkit on F5 BIG-IP APM devices, keeping a web shell in memory to evade file-based detection. The campaign is linked to CVE-2025-53521 and PoisonedRefresh. #F5BIGIPAPM #CVE202553521 #PoisonedRefresh
Explore
Sophos found F5 BIG-IP APM malware injecting a PHP web shell into memory, leaving disk files clean. Linked to CVE-2025-53521 and c05d5254, with indicators like apm_css.php3 and full_wt.php3. #F5 #BIGIPAPM #CVE202553521
