Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, f5, big-ip, rootkit, webshell, active-exploitation] ยท confidence: verified ยท affected_sectors: [technology, government, financial-services] ยท au_impact: true

Sophos and ESET analysed a Linux rootkit ("PoisonedRefresh") targeting F5 BIG-IP APM environments that intercepts PHP file loading and injects a fileless web shell directly into memory, avoiding disk writes and significantly reducing the detection surface. The malware โ€” assessed as a second-stage payload likely delivered via CVE-2025-53521, a critical F5 BIG-IP RCE flaw reclassified from a DoS problem in March 2026 โ€” hides key strings with RC4, hooks the Apache Portable Runtime module loader to gain execution before the host application's main(), intercepts PHP operations to conceal a web shell inside legitimate scripts, and creates a password-protected local socket backdoor with SELinux-modification persistence. ShadowServer reported roughly 795 BIG-IP APM endpoints remained exposed online in early September 2026.

Attribute Detail
Date Analysed 2026-09-08
Type Fileless web-shell rootkit on BIG-IP APM
Entry CVE CVE-2025-53521 (likely)
Exposure ~795 BIG-IP APM endpoints exposed (ShadowServer)
Source Sophos / ESET โ€” Tier 1/4

Source