Sophos dissects Linux rootkit that hides PHP web shells in BIG-IP APM environments

Summary
Sophos analyzed a Linux implant targeting BIG-IP APM webtop environments. It uses custom loading and runtime hooks to inject a PHP web shell into memory, while a local UNIX socket provides another route to an interactive shell.
Key points
- The implant targets Apache/PHP deployments in BIG-IP APM webtop environments. F5 associates related activity with CVE-2025-53521, an exploited unauthenticated RCE affecting BIG-IP APM when an access policy is configured on a virtual server.
- A custom ELF loader and hooks to __libc_start_main and Apache’s APR module loader let the malware activate early and wait for libphp to load.
- The implant hooks PHP file and memory operations to prepend a web shell to selected PHP files in memory; the files on disk can remain unchanged.
- The web shell accepts specially marked, encrypted HTTP POST requests and executes the decrypted content.
- A separate local UNIX socket at /run/bigtlog.pipe can redirect an authenticated connection to /bin/bash without opening a TCP listener.
- Sophos recommends following F5’s remediation and compromise-assessment guidance for potentially affected BIG-IP APM systems. It detects the implant as Linux/Agnt-IC; no specific threat actor attribution was established.
Article Details
- Attack Vectors
- A related installer component appears to infect /usr/sbin/httpd, persist across BIG-IP upgrade images, modify SELinux configurations, and deploy the analyzed second-stage payload.
- The implant uses a custom ELF loader and intercepts __libc_start_main to run before the host application's main() function.
- After Apache loads libphp, the implant patches runtime calls so that selected PHP files receive an embedded web shell in memory while their on-disk contents remain unchanged.
- The embedded web shell checks an HTTP request marker, decrypts the remaining request content, and executes it through PHP eval.
- A separate local UNIX domain socket backdoor authenticates a connection and redirects it to /bin/bash.
- Defensive Notes
- For potentially affected BIG-IP APM systems, follow F5's remediation and compromise-assessment guidance before applying generic Apache or PHP hardening.
- Correlate unusual requests to the identified .php3 endpoints with HTTP 201 responses claiming a text/css content type and repeated POST requests with unusual body sizes.
- Investigate Apache workers reading /proc/self/maps, temporarily changing libphp memory protections, creating /run/bigtlog.pipe, or spawning /bin/bash.
- Capture volatile evidence and compare process memory with on-disk files and modules; file scanning alone may miss the in-memory web shell.
- Treat the listed behaviors as investigatory leads, not standalone confirmation of compromise.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA256 | 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 | SHA-256 hash of the analyzed Linux implant sample. |
MITRE ATT&CK
T1014 · RootkitThe implant hooks startup and Apache/PHP runtime functions, patches libphp calls, and presents malicious PHP content in memory without changing the targeted scripts on disk.T1027 · Obfuscated Files or InformationThe implant stores operational strings encrypted with RC4 and decrypts them at runtime, hindering static string analysis.T1059.004 · Unix ShellAfter authentication through its local UNIX socket, the implant redirects the connection's standard streams to /bin/bash for interactive shell access.T1505.003 · Web ShellThe implant prepends a PHP web shell to targeted scripts in memory, enabling server-side execution through HTTP requests.T1554 · Compromise Host Software BinaryA related installer component appears to infect /usr/sbin/httpd with a malicious prefix while preserving the original executable for the implant's loader.
CVE
Malware
Vendors
Products
Apachea Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, functionBIG-IP APMThe malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows, suggesting it was developed for specific environments. F5 associates the relatedPHPimplant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking,