Summary
Sophos and ESET have jointly confirmed a Linux rootkit, named PoisonedRefresh by ESET, actively targeting F5 BIG-IP Access Policy Manager devices. The rootkit intercepts PHP file loading and injects a fileless web shell directly into Apache process memory, leaving no malicious files on disk and complicating standard forensic detection. Sophos assessed it as a likely second-stage payload deployed after initial compromise via CVE-2025-53521, a critical remote code execution flaw in BIG-IP APM. The Shadowserver Foundation tracked 795 internet-exposed BIG-IP APM endpoints vulnerable to CVE-2025-53521 at the time of publication.
Timeline
| Date | Event |
|---|---|
| 2025 | CVE-2025-53521 initially classified as a DoS vulnerability in F5 BIG-IP APM |
| Early 2026 | F5 reclassifies CVE-2025-53521 as a critical unauthenticated RCE flaw; CISA adds to KEV |
| Sep 8, 2026 | Sophos publishes PoisonedRefresh technical analysis; ESET independently confirms; 795 exposed endpoints tracked by Shadowserver |
What Changed
PoisonedRefresh hooks Linux, Apache, and PHP loading functions to intercept the Apache Portable Runtime module loader and inject a PHP web shell into memory rather than writing it to disk. Because APM script files on disk remain unmodified, the implant is not detectable by file-integrity monitoring or standard AV scanning. The rootkit uses RC4 to obfuscate key operational strings and gains execution before the host application main() function by intercepting __libc_start_main.
The rootkit also establishes a password-protected local Unix socket backdoor and can modify SELinux configuration and BIG-IP upgrade images, meaning it survives system upgrades unless specifically remediated. F5 tracks the associated adversary cluster as c05d5254. Defenders should look for anomalous Apache memory mappings, local Unix sockets, altered SELinux settings, modified upgrade images, and suspicious HTTP 201 responses disguised as CSS assets. Sophos advises preserving volatile memory evidence before rebooting any potentially compromised system.
Domain Intelligence
f5.com — 61.81
Score sits in the low-trust range. One threat intelligence source has flagged f5.com but the observation has not been independently corroborated; per WarmBadge's methodology, an unconfirmed single-source flag does not reduce the published score on its own. F5 is the vendor whose product is being targeted; the score reflects f5.com's domain trust posture, not the severity of the rootkit targeting its appliances.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
The Trust Observatory · thetrustobservatory.com · September 7, 2026