Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways

Summary

A newly discovered Linux rootkit is specifically targeting F5 BIG-IP Access Policy Management (APM) environments, enabling attackers to hide malicious web shells in memory without writing files to disk. This sophisticated technique leverages custom ELF loading and runtime code patching to achieve persistent access, making it difficult for traditional detection tools to identify. The activity is linked to the exploitation of CVE-2025-53521, a remote code execution vulnerability in BIG-IP APM.

IFF Assessment

FOE

This rootkit allows attackers to achieve stealthy, persistent access to sensitive enterprise identity gateways, posing a significant threat to defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: March 30, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should be aware of this advanced rootkit technique that evades file-based detection by manipulating PHP code in memory. Organizations using F5 BIG-IP APM should prioritize patching CVE-2025-53521 and implement memory-scanning or process-integrity monitoring solutions to detect such fileless threats.

Read Full Story →