Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
Reported exploitedF5 BIG-IP APMOur summary
Sophos has revealed that threat actors are exploiting F5 BIG-IP APM devices to install a sophisticated Linux rootkit named PoisonedRefresh. This campaign leverages CVE-2025-53521, an unauthenticated remote code execution vulnerability, to inject a web shell directly into memory, thereby avoiding detection by traditional file-based scanning tools.
The malware operates by hooking Apache’s Portable Runtime and modifying how PHP files like apm_css.php3 are loaded, effectively masking malicious code within legitimate scripts. Additionally, the implant establishes a Unix domain socket at /run/bigtlog.pipe to provide attackers with direct shell access without leaving standard network traces.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.