Dissecting a PHP web server rootkit (opens in a new tab)
Why readReverse-engineers a PHP rootkit that hooks Apache via libphp and APR module loading to survive F5 BIG-IP upgrades, tied to exploitation of CVE-2025-53521 in BIG-IP APM.
The implant gives on-demand server-side code execution like a web shell but does it through Apache and libphp module loading rather than a dropped script, and is purpose-built for BIG-IP APM webtop and upgrade workflows. Analysis puts the sample as a second stage; a related umount sample revealed an installer that infects /usr/sbin/httpd, persists across BIG-IP upgrade images and modifies SELinux configuration. F5 links the c05d5254 activity to BIG-IP APM systems hit by CVE-2025-53521, an exploited unauthenticated RCE where an access policy is bound to a virtual server, and Sophos tells affected operators to follow F5's compromise-assessment guidance before generic Apache or PHP hardening.
Indicators1
- Hashes
26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9