CVE Tools

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory

Help Net SecurityBy Sinisa Markovic

Reported exploitedF5 BIG-IP APM

Our summary

Sophos has revealed that threat actors are exploiting F5 BIG-IP APM devices to install a sophisticated Linux rootkit named PoisonedRefresh. This campaign leverages CVE-2025-53521, an unauthenticated remote code execution vulnerability, to inject a web shell directly into memory, thereby avoiding detection by traditional file-based scanning tools.

The malware operates by hooking Apache’s Portable Runtime and modifying how PHP files like apm_css.php3 are loaded, effectively masking malicious code within legitimate scripts. Additionally, the implant establishes a Unix domain socket at /run/bigtlog.pipe to provide attackers with direct shell access without leaving standard network traces.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store