Sophos and ESET analysed a Linux rootkit ("PoisonedRefresh") targeting F5 BIG-IP APM environments that intercepts PHP file loading and injects a fileless web shell directly into memory, avoiding disk writes and significantly reducing the detection surface. The malware โ assessed as a second-stage payload likely delivered via CVE-2025-53521, a critical F5 BIG-IP RCE flaw reclassified from a DoS problem in March 2026 โ hides key strings with RC4, hooks the Apache Portable Runtime module loader to gain execution before the host application's main(), intercepts PHP operations to conceal a web shell inside legitimate scripts, and creates a password-protected local socket backdoor with SELinux-modification persistence. ShadowServer reported roughly 795 BIG-IP APM endpoints remained exposed online in early September 2026.
| Attribute | Detail |
|---|---|
| Date | Analysed 2026-09-08 |
| Type | Fileless web-shell rootkit on BIG-IP APM |
| Entry CVE | CVE-2025-53521 (likely) |
| Exposure | ~795 BIG-IP APM endpoints exposed (ShadowServer) |
| Source | Sophos / ESET โ Tier 1/4 |