Incident
Published 2026-09-08
Verified 2026-09-19

F5 BIG-IP APM: PoisonedRefresh Linux rootkit / in-memory PHP web shell (Sophos/ESET)

BleepingComputer (8 September 2026) reports Sophos analysis of a Linux rootkit targeting F5 BIG-IP APM environments that intercepts PHP loading and injects a fileless web shell in memory so on-disk PHP files stay unchanged. ESET tracks the family as PoisonedRefresh. Sophos describes a separate installer/propagation stage that tampers with Apache /usr/sbin/httpd, SELinux policy, and persistence across BIG-IP upgrade images; the second stage uses RC4 string hiding, hooks __libc_start_main and apr_dso_load, and injects into APM webtop scripts such as apm_css.php3, full_wt.php3, and webtop_popup_css.php3. The web shell accepts magic requests, eval()s decrypted content, and returns HTTP 201 disguised as text/css; a password-protected local UNIX socket can spawn Bash without a TCP listener. Sophos says the payload was likely deployed after exploitation of CVE-2025-53521 (critical RCE that F5 reclassified from DoS in March). Shadowserver reportedly tracked about 795 internet-exposed BIG-IP APM endpoints still vulnerable to that CVE at time of writing. Hunt: Apache workers reading /proc/self/maps, changing libphp memory protections, creating /run/bigtlog.pipe, launching /bin/bash, unusual POSTs to targeted .php3 paths, or HTTP 201 + text/css responses. Wire: BleepingComputer; research: Sophos / ESET.

Product
F5 BIG-IP APM (Access Policy Manager) / Apache PHP webtop
Versions
Environments vulnerable to CVE-2025-53521 and/or showing PoisonedRefresh installer artefacts; confirm against F5 advisory for your TMOS branch
Exploited in Australia?
unknown
Patch to
Patch CVE-2025-53521 per F5; hunt Sophos IoCs (httpd integrity, SELinux changes, /run/bigtlog.pipe, magic .php3 POSTs, HTTP 201 text/css); rebuild from known-good images if compromised

Primary: BleepingComputer — BIG-IP APM PoisonedRefresh rootkit (8 Sep 2026) · Vendor: F5 security advisories portal · CVE: CVE-2025-53521 · The Hacker News (9 Sep 2026)

breaches network cloud identity