The web shell never exists on disk, and the CVE that let it in was filed as a denial of service
2026-09-09Security
Sophos documented malware that infects the Apache binary on F5 BIG-IP APM, hooks the runtime as PHP loads, and writes a web shell into memory in front of three real scripts. File integrity checks pass. The entry point, CVE-2025-53521, was published as a DoS in October 2025 and reclassified as unauthenticated RCE five months later.