Find notable cyber news and cases, enriched with sources, timelines, and signals.

PoisonedRefresh Linux rootkit on F5 BIG-IP APM

Malware Activity
First reported
Last updated
Happening score
H score 31
2 unique sources, 2 articles

Summary

Hide ▲

The PoisonedRefresh malware activity targets F5 BIG-IP APM appliances and uses a fileless PHP web shell that Sophos said is injected into memory rather than written to disk. Sophos also described a related installer that infects /usr/sbin/httpd, hooks apr_dso_load, and opens a local backdoor at /run/bigtlog.pipe that can spawn /bin/bash. The activity is linked to CVE-2025-53521, which F5 said was exploited and reclassified as remote code execution on March 27, 2026. F5’s March indicators and Sophos’s analysis overlap on apm_css.php3, full_wt.php3, and webtop_popup_css.php3, while Sophos said file checks can miss the shell because it can exist only in memory.

Related Happenings

UniFi OS Server unauthenticated root RCE chain (multiple vulnerabilities)

Vulnerability
H score25 First: 08.06.2026 18:51 Last: 08.06.2026 18:51 Sources 1

About this happening: UniFi OS Server is exposed to an unauthenticated root RCE chain that combines CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, putting versions 5.0.6 and...

Latest development: 24.06.2026 15:32

CISA added CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to the Known Exploited Vulnerabilities (KEV) catalog after warnings that threat actors were targeting UniFi OS Server devices and multiple users reported in-the-wild exploitation that created rogue administrator accounts named 'John Sim' on affected Ubiquiti systems.

F5 BIG-IP APM active exploitation wave (CVE-2025-53521)

Exploitation Wave
H score79 First: 02.04.2026 11:25 Last: 02.04.2026 11:25 Sources 1

How related: F5 has linked the c05d5254 activity to appliances affected by CVE-2025-53521, Sophos said.

About this happening: CVE-2025-53521 is being exploited against F5 BIG-IP APM systems, and F5 says new information in March 2026 changed the flaw from denial of service to remote...

NoVoice Android malware hidden in Google Play apps

Malware Activity
H score21 First: 01.04.2026 21:07 Last: 01.04.2026 21:07 Sources 1

About this happening: NoVoice Android malware was found hidden in more than 50 Google Play apps, exposing at least 2.3 million downloads to compromise. After installation, it used old And...

F5 BIG-IP APM unauthenticated RCE (CVE-2025-53521)

Vulnerability
H score84 First: 30.03.2026 10:07 Last: 30.03.2026 10:07 Sources 1

How related: F5 has linked the c05d5254 activity to appliances affected by CVE-2025-53521, Sophos said.

About this happening: CVE-2025-53521 is an unauthenticated remote code execution flaw in F5 BIG-IP APM deployments with an access policy on a virtual server, including Appliance mode. F...

CISA KEV patch directive for CVE-2025-53521

Advisory/Mitigation
H score86 First: 30.03.2026 10:07 Last: 30.03.2026 10:07 Sources 1

About this happening: CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...

Timeline

  1. 08.09.2026 23:08 3 articles · 13h ago

    Sophos details PoisonedRefresh Linux rootkit on F5 BIG-IP APM devices

    Technical Analysis Update

    Sophos analyzed a PoisonedRefresh Linux rootkit targeting F5 BIG-IP APM devices and assessed it as a second-stage payload likely deployed after CVE-2025-53521 exploitation. The malware infected Apache /usr/sbin/httpd on BIG-IP APM systems, hooked __libc_start_main and the Apache Portable Runtime (APR) module loader apr_dso_load, modified SELinux configurations, persisted across BIG-IP upgrade images, and injected a PHP web shell into memory.

    Show sources