INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

PoisonedRefresh: Injects PHP Web Shells into F5 BIG-IP APM Server

| 2026-09-09 08:50 HIGH HIGH
Executive Summary
AI-generated
The PoisonedRefresh rootkit has been identified as a sophisticated malware that targets compromised F5 BIG-IP APM server environments, injecting PHP web shells into the systems and leaving no disk artifacts. This implant demonstrates how modern Linux malware can deliver familiar attacker capabilities through sophisticated delivery mechanisms. The malware is believed to have been developed for specific environments, such as those featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows. F5 has published remediation and compromise assessment guidance for CVE-2025-53521, an exploited unauthenticated remote code execution flaw in BIG-IP APM when an access policy is configured on a virtual server. The initial access vector is CVE-2025-53521, an unauthenticated remote code execution flaw in BIG-IP APM when an access policy is configured on a virtual server.
Technical Mitigations AI-generated
I can provide the technical mitigations as requested. However, please note that I'll need to condense or summarize the information provided in the articles to fit within the required format. Here are 3-5 technical mitigations for the PoisonedRefresh and Dissecting a PHP web server rootkit: * Implement secure coding practices: Ensure that all Apache and PHP components are updated with the latest security patches, including CVE-2025-53521. * Use secure configuration options: Configure BIG-IP APM environments to use secure configuration options, such as SELinux and AppArmor, to limit privileges and prevent exploitation of vulnerabilities like CVE-2025-53521. * Monitor for suspicious activity: Regularly monitor BIG-IP APM environments for suspicious activity, including unusual access patterns or changes in Apache process behavior, which could indicate the presence of a malware implant like PoisonedRefresh. * Implement network segmentation: Segment the network to isolate BIG-IP APM environments from other systems and networks, reducing the attack surface and making it more difficult for attackers to exploit vulnerabilities like CVE-2025-53521. * Use secure file system options: Configure the file system on BIG-IP APM servers to use secure options, such as encrypted storage or isolated file systems, to prevent malware implants from accessing sensitive data.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

26bd5b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ld•••••.so
bi•••••.pipe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
China ChopperChina Chopper CVE-2025-53521CVE-2025-53521
Target & Sectors
CN
Incident Timeline
‎September 8, 2026
The second-stage malware, dubbed PoisonedRefresh by ESET, infects a modified Linux umount binary and embeds itself in BIG-IP upgrade images to survive device updates.
infrastructure Linux
organisation SophosLabs
organisation ESET
organisation Linux/Agnt-IC
organisation Sophos
organisation SELinux
organisation CVE-2025
organisation CVE-2025-53521
organisation SHA-256
organisation APR
organisation BIG-IP APM
organisation The Shadowserver Foundation
infrastructure 795 exposed endpoints
organisation F5
organisation TCP
organisation CSS
organisation Teams
organisation Content-Type
organisation ELF
organisation SecurityAffairs
‎September 09, 2026
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM server memory.
infrastructure Linux
tactic T1014 - Rootkit
tactic T1584.004 - Server
organisation PHP
organisation APM Apache
‎2026/09/09
The threat actors used a custom Linux fileless rootkit to inject PHP web shells into F5 BIG-IP APM servers.
infrastructure Linux
organisation PoisonedRefresh
organisation Linux/Agnt-IC
organisation SophosLabs
organisation BIG-IP Access Policy Management
organisation APM
organisation API
organisation Ordinary Linux
organisation PHP
organisation ESET
organisation CVE-2025
organisation JSP
organisation ASP
organisation SELinux
organisation BIG-IP
organisation AF_UNIX
organisation TCP
organisation CSS
organisation Content-Type
organisation ELF
organisation 0x5430
organisation CMS
organisation UNIX
organisation Apache/PHP
organisation RWX
organisation wSLjN1beuR
organisation apr_time_now
organisation Repeated POST
organisation RX
data_breach 16 byte
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
795
Exposed Endpoints
Metrics
data_breach
16
Byte
Intelligence Sources