Executive Summary
In September 2026, security researchers discovered a sophisticated Linux rootkit campaign targeting F5 BIG-IP APM devices. Attackers exploited CVE-2025-53521, a critical remote code execution vulnerability, to deploy the 'PoisonedRefresh' rootkit that injects fileless web shells directly into memory. The malware intercepts PHP file operations, modifies scripts in memory without altering disk files, and creates password-protected backdoors while maintaining persistence across system upgrades. This advanced attack demonstrates the evolution of infrastructure targeting, as threat actors increasingly focus on critical network appliances that provide extensive access to organizational traffic and systems. With 795 vulnerable endpoints still exposed online, this incident highlights the urgent need for robust patch management and enhanced monitoring of network infrastructure devices.
Why This Matters Now
Infrastructure attacks are escalating rapidly, with threat actors targeting network appliances to establish persistent footholds in enterprise environments. The fileless, memory-resident techniques used in this campaign represent sophisticated evasion methods that traditional security tools struggle to detect.
Attack Path Analysis
Attackers exploited CVE-2025-53521 in F5 BIG-IP APM systems to deploy a sophisticated Linux rootkit that intercepts PHP operations and injects fileless web shells into memory. The malware achieved persistence across system upgrades, established covert command channels through UNIX sockets, and maintained stealth by modifying legitimate scripts in-memory without disk changes.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2025-53521, a critical remote code execution vulnerability in F5 BIG-IP APM devices exposed to the internet
Related CVEs
CVE-2025-53521
CVSS 9.8A critical remote code execution vulnerability in F5 BIG-IP APM systems that allows unauthorized attackers to execute arbitrary commands on affected devices.
Affected Products:
F5 Networks BIG-IP APM – Multiple versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Process Injection
Boot or Logon Initialization Scripts: RC Scripts
Rootkit
Server Software Component: Web Shell
Impair Defenses: Indicator Blocking
Command and Scripting Interpreter: Unix Shell
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Vulnerability Management Process
Control ID: 6.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Asset Management and Visibility
Control ID: ZT.AM-03
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
F5 BIG-IP APM rootkit enables persistent access to critical load balancers protecting financial applications, facilitating data exfiltration and lateral movement across payment systems.
Health Care / Life Sciences
Advanced persistent threat targeting F5 devices creates stealth backdoors in healthcare networks, bypassing HIPAA controls and enabling unauthorized access to patient data systems.
Government Administration
Linux rootkit deployment on government F5 infrastructure allows covert command execution and data theft while evading detection across critical public sector applications.
Telecommunications
Memory-resident web shells in F5 APM devices compromise telecom network security, enabling threat actors to intercept communications and maintain persistent network access.
Sources
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkithttps://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/Verified
- Dissecting a PHP web server rootkit targeting F5 BIG-IP APMhttps://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkitVerified
- ESET Research - PoisonedRefresh Analysishttps://infosec.exchange/@ESETresearch/116460555146536345Verified
- ShadowServer F5 BIG-IP APM Vulnerability Trackerhttps://dashboard.shadowserver.org/statistics/iot-devices/time-series/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this F5 BIG-IP compromise by constraining lateral movement paths and limiting east-west traffic flow between network segments. The segmentation controls could reduce the scope of rootkit propagation across critical infrastructure devices.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise of the F5 BIG-IP device would likely still occur, but the attack scope could be constrained through network segmentation policies that limit reachability to other infrastructure components from compromised edge devices.
Control: Zero Trust Segmentation
Mitigation: System-level persistence would likely remain achievable on the compromised device, but zero trust segmentation could constrain the privileges and network access available to the rootkit, limiting its operational scope within the infrastructure.
Control: East-West Traffic Security
Mitigation: Lateral movement between BIG-IP devices and other network segments would likely be significantly constrained through east-west traffic inspection and micro-segmentation policies that reduce the rootkit's ability to spread across infrastructure components.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely be constrained through network visibility controls that could detect and limit suspicious HTTP patterns and unauthorized outbound communications from the compromised infrastructure device.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained through egress security policies that monitor and control outbound data flows from compromised infrastructure devices, reducing the volume and scope of potential data theft.
The overall impact would likely be reduced to isolated infrastructure devices rather than widespread network compromise, with the persistent backdoor's reach constrained to segmented network boundaries and limited lateral access paths.
Impact at a Glance
Affected Business Functions
- Network Security Infrastructure
- Application Delivery Management
- Remote Access Services
- Web Application Protection
Estimated downtime: 7 days
Estimated loss: N/A
Potential exposure of network traffic, authentication credentials, and internal application data processed through compromised F5 BIG-IP APM devices. The rootkit enables persistent backdoor access and server-side code execution capabilities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between compromised infrastructure devices and critical workloads
- • Deploy Multicloud Visibility & Control solutions to detect anomalous interactions and suspicious automation targeting management interfaces
- • Enable Egress Security & Policy Enforcement to block unauthorized outbound communications from infrastructure devices to external command and control servers
- • Utilize Threat Detection & Anomaly Response capabilities to baseline normal APM device behavior and alert on memory protection changes or unusual process execution
- • Apply Encrypted Traffic inspection and East-West Traffic Security controls to monitor inter-device communications and detect covert channels in hybrid network environments



