Fileless Rootkit ‘PoisonedRefresh’ Found Hiding Web Shells in F5 BIG-IP Memory

Researchers at Sophos and ESET detailed a stealthy Linux rootkit, dubbed PoisonedRefresh, discovered on compromised F5 BIG-IP Access Policy Manager (APM) appliances, Help Net Security reported. The implant hooks Apache’s PHP module loader to inject a web shell directly into memory, never writing to disk, making it difficult to detect with conventional file-based scanning.

The activity is tied to exploitation of CVE-2025-53521, a critical unauthenticated remote-code-execution flaw that F5 originally classified as a denial-of-service issue before reclassifying it. F5 has confirmed exploitation, and Shadowserver was tracking 795 internet-exposed vulnerable BIG-IP APM endpoints as of September 7, 2026. The findings were independently corroborated by BleepingComputer, SecurityAffairs and CybelAngel.

Why it matters: F5 BIG-IP APM is widely deployed by government, financial and critical-infrastructure organizations to manage secure remote access. A memory-resident rootkit that survives file-based detection on this class of device represents a significant, hard-to-spot foothold inside networks that are supposed to be tightly controlled.

Source: Help Net Security, September 9, 2026.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *