Malware targeting F5 BIG-IP APM appliances, tracked as c05d5254 and linked to CVE-2025-53521 (a critical remote code execution flaw rated 9.8 on CVSS 3.1), evades detection by injecting a PHP web shell into Apache's memory rather than writing it to disk, meaning file scans return clean results. Sophos found that the malware hooks into Apache's internals to intercept PHP file loading, inserting the web shell before the legitimate script content in memory, while also providing a secondary backdoor via a local Unix socket connected to bash. Organizations are advised to run F5's sys-eicheck integrity tool, compare in-memory modules against on-disk copies, and submit a qkview report to F5, as patching alone does not confirm an appliance was not compromised beforehand and the malware may survive firmware upgrades.