Exploited in the wild F5 BIG-IP APM malware F5 zero-day
Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
CVE Tools coverage
Sophos has revealed that threat actors are exploiting F5 BIG-IP APM devices to install a sophisticated Linux rootkit named PoisonedRefresh. This campaign leverages CVE-2025-53521, an unauthenticated remote code execution vulnerability, to inject a web shell directly into memory, thereby avoiding detection by traditional file-based scanning tools.
The malware operates by hooking Apache’s Portable Runtime and modifying how PHP files like apm_css.php3 are loaded, effectively masking malicious code within legitimate scripts. Additionally, the implant establishes a Unix domain socket at /run/bigtlog.pipe to provide attackers with direct shell access without leaving standard network traces.