F5 BIG-IP APM: in-memory PHP web shell on webtop scripts (Sophos / c05d5254)
Sophos analysis (published ~7 September 2026; THN 9 September) describes malware on compromised F5 BIG-IP Access Policy Manager appliances that injects a PHP web shell into memory when Apache loads APM webtop scripts apm_css.php3, full_wt.php3 or webtop_popup_css.php3 — so on-disk file hashes can look clean. F5 previously tracked related activity as malware family c05d5254 and warned those three scripts can be modified or hold in-memory-only shells (IoC list from March). Defenders must not rely on disk-only webshell scans; compare runtime/Apache memory and hunt the F5 IoCs. Related CVE context in wires includes CVE-2025-53521 in some coverage. Watchlist: F5. Primary research: Sophos; wire: THN; vendor IoC context: F5.
- Product
- F5 BIG-IP Access Policy Manager (APM webtop)
- Versions
- Compromised APM appliances loading named webtop PHP scripts (see F5 c05d5254 IoCs)
- Exploited in Australia?
- unknown
- Patch to
- Hunt F5 c05d5254 IoCs; inspect runtime/memory not only disk; rebuild/rotate creds on confirmed compromise; keep BIG-IP patched
Primary: Sophos — in-memory PHP web server rootkit (BIG-IP APM) · CVE: CVE-2025-53521 · The Hacker News (9 Sep 2026)
