c05d5254 is an F5 tracking designation for malware deployed against F5 BIG-IP Access Policy Manager appliances following exploitation of CVE-2025-53521, an unauthenticated remote-code-execution vulnerability. It modifies the Apache HTTP Server executable so malicious code executes before Apache’s normal logic. The implant hooks Apache Portable Runtime dynamic-library loading, waits for PHP to load, then intercepts PHP file operations to prepend a PHP web shell to selected BIG-IP APM webtop scripts in memory. This enables the web shell to operate while the corresponding files on disk can remain unchanged, evading conventional file-integrity checks. The web shell accepts specially formatted encrypted request data and executes supplied commands, returning HTTP 201 responses with a CSS content type to blend command-and-control traffic into apparent stylesheet activity. The malware can also create a local Unix socket that provides an authenticated interactive shell through Bash without exposing a network listening port. Related samples analyzed as PoisonedRefresh were reported to alter BIG-IP installation media and disable SELinux, potentially supporting persistence across upgrades or propagation through installation images; the relationship to c05d5254 is reported as related rather than conclusively identical. No threat actor attribution has been established. The malware targets Linux-based F5 BIG-IP APM systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
F5 listed the three PHP scripts as indicators of compromise associated with malware it tracks under the designation c05d5254. F5 linked this activity to devices affected by CVE-2025-53521.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
По проверка на однапред дефиниран токен, тој го поврзува socket-от со /bin/bash, овозможувајќи интерактивна shell сесија без отворање мрежен порт.
Веб-шелот го чита необработеното тело на барањето, проверува дали содржи кратка ознака, го дешифрира остатокот и го извршува.
Како одговор испраќа HTTP статус 201 и тип на содржина CSS, па целата комуникација изгледа како барање за stylesheet.
The company noted that in cases of the successful deployment of malicious software tracked as c05d5254, organizations may detect files on disk such as /run/bigtlog.pipe and /run/bigstart.ltm, as well as mismatches of file sizes, hashes, and timestamps for known good versions of /usr/bin/umount and /usr/sbin/httpd.
It replies with HTTP status 201 and a CSS content type, so the exchange looks like a request for a stylesheet.
Малициозниот софтвер исто така отвора локален socket на /run/bigtlog.pipe... го поврзува socket-от со /bin/bash.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
F5's designation for malware activity on BIG-IP APM appliances. The described implant injects a PHP web shell into the in-memory representation of legitimate PHP scripts, evading disk-based integrity checks, and is associated with modified Apache/httpd and umount binaries.
Referenced as malicious software observed in exploitation of CVE-2025-53521 against F5 BIG-IP APM systems.
Malicious software tracked by Fortinet as c05d5254 that is deployed after successful exploitation of CVE-2025-53521 on BIG-IP systems, leaving specific files and modified binaries as indicators of compromise.
Malicious software tracked by F5 as c05d5254 that has been deployed following exploitation of CVE-2025-53521 on BIG-IP systems; associated with file artifacts and modified binaries on compromised devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.