Hackers use likely CVE-2025-53521 access on F5 BIG-IP APM devices to install a memory-injecting Linux rootkit

Hackers are breaching F5 BIG-IP APM devices and installing a Linux rootkit that hides a web shell in memory instead of writing it to disk. Sophos and ESET analyzed the malware, identified by ESET as PoisonedRefresh, and say it was likely deployed after exploitation of CVE-2025-53521, a critical remote-code-execution flaw in BIG-IP APM that F5 had earlier classified as a denial-of-service issue. The malware hooks Apache and PHP loading, modifies SELinux settings, persists across BIG-IP upgrades, and uses hidden requests to execute commands while blending responses in normal-looking CSS traffic.
Why it matters: Organizations using internet-exposed F5 BIG-IP APM systems may already be compromised in a way that is hard to detect with file-based scans. This is urgent: patch or mitigate CVE-2025-53521, hunt for the listed indicators such as /run/bigtlog.pipe and unusual HTTP 201 text/css responses, and assume credential or appliance compromise if exposure is confirmed.

Sources

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
info@thehackernews.com (The Hacker News) 2026.09.09 97% relevant
This appears to be the same underlying incident: attackers compromising F5 BIG-IP APM appliances and using malware that injects a PHP web shell into memory to evade disk-based detection. The article reinforces the observed post-compromise technique and the affected product family rather than establishing a separate event.
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Bill Toulas 2026.09.08 100% relevant
This article establishes a distinct story by tying active BIG-IP APM compromises to a specific malware family and likely exploitation path, with new technical evidence of post-exploitation tradecraft and defender indicators.
← Back to all stories