Attackers compromised F5 BIG-IP Access Policy Manager (APM) webtop servers and deployed the Linux rootkit PoisonedRefresh, which injects a PHP web shell into Apache process memory while leaving the corresponding APM script files unchanged on disk. F5 linked the activity to exploitation of CVE-2025-53521, an unauthenticated remote-code-execution flaw previously classified as a denial-of-service issue; Sophos assessed the rootkit as a likely second-stage payload. The campaign has not been attributed to a named threat actor.
The implant hooks Linux, Apache, and PHP loading functions to run attacker commands, and provides a password-protected local Unix-socket backdoor. Related tooling can modify the HTTP server binary, SELinux configuration, and BIG-IP upgrade images for persistence. Defenders should preserve volatile evidence and investigate anomalous Apache memory mappings and child processes, local sockets, altered SELinux settings and upgrade images, and suspicious HTTP 201 responses disguised as CSS assets.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
SophosLabs published technical details of PoisonedRefresh, including its memory-only injection of an encrypted PHP web shell into BIG-IP APM webtop scripts and its authenticated local UNIX-socket backdoor. The analysis also disclosed persistence and detection indicators, including the /run/bigtlog.pipe socket, modified SELinux settings, altered upgrade images, and anomalous HTTP 201 CSS-like responses.
The Shadowserver Foundation observed 795 internet-exposed F5 BIG-IP APM endpoints vulnerable to CVE-2025-53521.
CISA added CVE-2025-53521 to its Known Exploited Vulnerabilities catalog after F5 confirmed exploitation of the BIG-IP APM vulnerability.
F5 initially disclosed CVE-2025-53521 as a denial-of-service vulnerability affecting BIG-IP APM configurations with an access policy assigned to a virtual server. F5 later reclassified it as an actively exploited unauthenticated remote-code-execution vulnerability.
Sophos analysts identified a Linux rootkit, named PoisonedRefresh by ESET, targeting F5 BIG-IP APM webtop servers. Sophos assessed it as a likely second-stage payload following exploitation of CVE-2025-53521; the activity was not attributed to a named threat actor.
F5 Networks reclassified CVE-2025-53521 from a denial-of-service issue. The vulnerability was subsequently described as a critical unauthenticated remote-code-execution flaw affecting BIG-IP devices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
9 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecsoonline.com
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcemkd-cirt.mk
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.