PoisonedRefresh Linux rootkit on F5 BIG-IP APM
Malware Activity
Summary
Hide ▲
Show ▼
The PoisonedRefresh malware activity targets F5 BIG-IP APM appliances and uses a fileless PHP web shell that Sophos said is injected into memory rather than written to disk. Sophos also described a related installer that infects /usr/sbin/httpd, hooks apr_dso_load, and opens a local backdoor at /run/bigtlog.pipe that can spawn /bin/bash. The activity is linked to CVE-2025-53521, which F5 said was exploited and reclassified as remote code execution on March 27, 2026. F5’s March indicators and Sophos’s analysis overlap on apm_css.php3, full_wt.php3, and webtop_popup_css.php3, while Sophos said file checks can miss the shell because it can exist only in memory.
Related Happenings
UniFi OS Server unauthenticated root RCE chain (multiple vulnerabilities)
Vulnerability
H score25
First: 08.06.2026 18:51
Last: 08.06.2026 18:51
Sources 1
About this happening:
UniFi OS Server is exposed to an unauthenticated root RCE chain that combines CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, putting versions 5.0.6 and...
UniFi OS Server unauthenticated root RCE chain (multiple vulnerabilities)
VulnerabilityAbout this happening: UniFi OS Server is exposed to an unauthenticated root RCE chain that combines CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, putting versions 5.0.6 and...
Latest development: 24.06.2026 15:32
CISA added CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to the Known Exploited Vulnerabilities (KEV) catalog after warnings that threat actors were targeting UniFi OS Server devices and multiple users reported in-the-wild exploitation that created rogue administrator accounts named 'John Sim' on affected Ubiquiti systems.
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation Wave
H score79
First: 02.04.2026 11:25
Last: 02.04.2026 11:25
Sources 1
How related:
F5 has linked the c05d5254 activity to appliances affected by CVE-2025-53521, Sophos said.
About this happening:
CVE-2025-53521 is being exploited against F5 BIG-IP APM systems, and F5 says new information in March 2026 changed the flaw from denial of service to remote...
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation WaveHow related: F5 has linked the c05d5254 activity to appliances affected by CVE-2025-53521, Sophos said.
About this happening: CVE-2025-53521 is being exploited against F5 BIG-IP APM systems, and F5 says new information in March 2026 changed the flaw from denial of service to remote...
NoVoice Android malware hidden in Google Play apps
Malware Activity
H score21
First: 01.04.2026 21:07
Last: 01.04.2026 21:07
Sources 1
About this happening:
NoVoice Android malware was found hidden in more than 50 Google Play apps, exposing at least 2.3 million downloads to compromise. After installation, it used old And...
NoVoice Android malware hidden in Google Play apps
Malware ActivityAbout this happening: NoVoice Android malware was found hidden in more than 50 Google Play apps, exposing at least 2.3 million downloads to compromise. After installation, it used old And...
F5 BIG-IP APM unauthenticated RCE (CVE-2025-53521)
Vulnerability
H score84
First: 30.03.2026 10:07
Last: 30.03.2026 10:07
Sources 1
How related:
F5 has linked the c05d5254 activity to appliances affected by CVE-2025-53521, Sophos said.
About this happening:
CVE-2025-53521 is an unauthenticated remote code execution flaw in F5 BIG-IP APM deployments with an access policy on a virtual server, including Appliance mode. F...
F5 BIG-IP APM unauthenticated RCE (CVE-2025-53521)
VulnerabilityHow related: F5 has linked the c05d5254 activity to appliances affected by CVE-2025-53521, Sophos said.
About this happening: CVE-2025-53521 is an unauthenticated remote code execution flaw in F5 BIG-IP APM deployments with an access policy on a virtual server, including Appliance mode. F...
CISA KEV patch directive for CVE-2025-53521
Advisory/Mitigation
H score86
First: 30.03.2026 10:07
Last: 30.03.2026 10:07
Sources 1
About this happening:
CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...
CISA KEV patch directive for CVE-2025-53521
Advisory/MitigationAbout this happening: CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...
Timeline
-
08.09.2026 23:08 3 articles · 13h ago
Sophos details PoisonedRefresh Linux rootkit on F5 BIG-IP APM devices
Technical Analysis UpdateSophos analyzed a PoisonedRefresh Linux rootkit targeting F5 BIG-IP APM devices and assessed it as a second-stage payload likely deployed after CVE-2025-53521 exploitation. The malware infected Apache /usr/sbin/httpd on BIG-IP APM systems, hooked __libc_start_main and the Apache Portable Runtime (APR) module loader apr_dso_load, modified SELinux configurations, persisted across BIG-IP upgrade images, and injected a PHP web shell into memory.
Show sources
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit — www.bleepingcomputer.com — 08.09.2026 23:08
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit — www.bleepingcomputer.com — 08.09.2026 23:08
- F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans — thehackernews.com — 09.09.2026 10:36