Executive Summary

In September 2026, security researchers discovered a sophisticated Linux rootkit campaign targeting F5 BIG-IP APM devices. Attackers exploited CVE-2025-53521, a critical remote code execution vulnerability, to deploy the 'PoisonedRefresh' rootkit that injects fileless web shells directly into memory. The malware intercepts PHP file operations, modifies scripts in memory without altering disk files, and creates password-protected backdoors while maintaining persistence across system upgrades. This advanced attack demonstrates the evolution of infrastructure targeting, as threat actors increasingly focus on critical network appliances that provide extensive access to organizational traffic and systems. With 795 vulnerable endpoints still exposed online, this incident highlights the urgent need for robust patch management and enhanced monitoring of network infrastructure devices.

Why This Matters Now

Infrastructure attacks are escalating rapidly, with threat actors targeting network appliances to establish persistent footholds in enterprise environments. The fileless, memory-resident techniques used in this campaign represent sophisticated evasion methods that traditional security tools struggle to detect.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The rootkit operates entirely in memory without writing malicious code to disk, making it extremely difficult to detect using traditional file-based security tools.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of this F5 BIG-IP compromise by constraining lateral movement paths and limiting east-west traffic flow between network segments. The segmentation controls could reduce the scope of rootkit propagation across critical infrastructure devices.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial compromise of the F5 BIG-IP device would likely still occur, but the attack scope could be constrained through network segmentation policies that limit reachability to other infrastructure components from compromised edge devices.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: System-level persistence would likely remain achievable on the compromised device, but zero trust segmentation could constrain the privileges and network access available to the rootkit, limiting its operational scope within the infrastructure.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement between BIG-IP devices and other network segments would likely be significantly constrained through east-west traffic inspection and micro-segmentation policies that reduce the rootkit's ability to spread across infrastructure components.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control communications would likely be constrained through network visibility controls that could detect and limit suspicious HTTP patterns and unauthorized outbound communications from the compromised infrastructure device.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts would likely be constrained through egress security policies that monitor and control outbound data flows from compromised infrastructure devices, reducing the volume and scope of potential data theft.

Impact (Mitigations)

The overall impact would likely be reduced to isolated infrastructure devices rather than widespread network compromise, with the persistent backdoor's reach constrained to segmented network boundaries and limited lateral access paths.

Impact at a Glance

Affected Business Functions

  • Network Security Infrastructure
  • Application Delivery Management
  • Remote Access Services
  • Web Application Protection
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of network traffic, authentication credentials, and internal application data processed through compromised F5 BIG-IP APM devices. The rootkit enables persistent backdoor access and server-side code execution capabilities.

Recommended Actions

  • Implement Zero Trust Segmentation to prevent lateral movement between compromised infrastructure devices and critical workloads
  • Deploy Multicloud Visibility & Control solutions to detect anomalous interactions and suspicious automation targeting management interfaces
  • Enable Egress Security & Policy Enforcement to block unauthorized outbound communications from infrastructure devices to external command and control servers
  • Utilize Threat Detection & Anomaly Response capabilities to baseline normal APM device behavior and alert on memory protection changes or unusual process execution
  • Apply Encrypted Traffic inspection and East-West Traffic Security controls to monitor inter-device communications and detect covert channels in hybrid network environments

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image