Sophos dissects Linux rootkit that hides PHP web shells in BIG-IP APM environments

· Original article ↗

Summary

Sophos analyzed a Linux implant targeting BIG-IP APM webtop environments. It uses custom loading and runtime hooks to inject a PHP web shell into memory, while a local UNIX socket provides another route to an interactive shell.

Key points

  • The implant targets Apache/PHP deployments in BIG-IP APM webtop environments. F5 associates related activity with CVE-2025-53521, an exploited unauthenticated RCE affecting BIG-IP APM when an access policy is configured on a virtual server.
  • A custom ELF loader and hooks to __libc_start_main and Apache’s APR module loader let the malware activate early and wait for libphp to load.
  • The implant hooks PHP file and memory operations to prepend a web shell to selected PHP files in memory; the files on disk can remain unchanged.
  • The web shell accepts specially marked, encrypted HTTP POST requests and executes the decrypted content.
  • A separate local UNIX socket at /run/bigtlog.pipe can redirect an authenticated connection to /bin/bash without opening a TCP listener.
  • Sophos recommends following F5’s remediation and compromise-assessment guidance for potentially affected BIG-IP APM systems. It detects the implant as Linux/Agnt-IC; no specific threat actor attribution was established.

Article Details

Attack Vectors
  • A related installer component appears to infect /usr/sbin/httpd, persist across BIG-IP upgrade images, modify SELinux configurations, and deploy the analyzed second-stage payload.
  • The implant uses a custom ELF loader and intercepts __libc_start_main to run before the host application's main() function.
  • After Apache loads libphp, the implant patches runtime calls so that selected PHP files receive an embedded web shell in memory while their on-disk contents remain unchanged.
  • The embedded web shell checks an HTTP request marker, decrypts the remaining request content, and executes it through PHP eval.
  • A separate local UNIX domain socket backdoor authenticates a connection and redirects it to /bin/bash.
Defensive Notes
  • For potentially affected BIG-IP APM systems, follow F5's remediation and compromise-assessment guidance before applying generic Apache or PHP hardening.
  • Correlate unusual requests to the identified .php3 endpoints with HTTP 201 responses claiming a text/css content type and repeated POST requests with unusual body sizes.
  • Investigate Apache workers reading /proc/self/maps, temporarily changing libphp memory protections, creating /run/bigtlog.pipe, or spawning /bin/bash.
  • Capture volatile evidence and compare process memory with on-disk files and modules; file scanning alone may miss the in-memory web shell.
  • Treat the listed behaviors as investigatory leads, not standalone confirmation of compromise.

Indicators of compromise

TypeIndicatorContext
SHA25626bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9SHA-256 hash of the analyzed Linux implant sample.

MITRE ATT&CK

CVE

Malware

Vendors

Products

Related Articles