CVE Tools
Back to feed
Exploited in the wild F5 BIG-IP APM malware F5 Networks network-edge

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

BleepingComputer·By Bill Toulas··3 min read
CVE Tools coverage

Security researchers have identified active exploitation of F5 BIG-IP APM devices where attackers leverage the critical remote code execution flaw CVE-2025-53521 to deploy a sophisticated Linux rootkit. Dubbed 'PoisonedRefresh' by ESET, this second-stage payload uses fileless techniques to intercept PHP file loading via Apache APR hooks, effectively injecting a hidden web shell directly into memory without writing malicious code to disk.

Sophos analysis reveals that the implant modifies SELinux configurations to persist across upgrades and establishes a password-protected local UNIX socket for interactive Bash access, avoiding standard TCP listeners. Defenders should monitor for specific indicators such as unusual POST requests to .php3 endpoints returning HTTP 201 with text/css content types, and note that approximately 795 vulnerable endpoints remained exposed online recently.