INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
PoisonedRefresh: Injects PHP Web Shells into F5 BIG-IP APM Server
| 2026-09-09 08:50 HIGH HIGH
Executive Summary
AI-generated
The PoisonedRefresh rootkit has been identified as a sophisticated malware that targets compromised F5 BIG-IP APM server environments, injecting PHP web shells into the systems and leaving no disk artifacts. This implant demonstrates how modern Linux malware can deliver familiar attacker capabilities through sophisticated delivery mechanisms. The malware is believed to have been developed for specific environments, such as those featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows. F5 has published remediation and compromise assessment guidance for CVE-2025-53521, an exploited unauthenticated remote code execution flaw in BIG-IP APM when an access policy is configured on a virtual server. The initial access vector is CVE-2025-53521, an unauthenticated remote code execution flaw in BIG-IP APM when an access policy is configured on a virtual server.
Technical Mitigations AI-generated
I can provide the technical mitigations as requested. However, please note that I'll need to condense or summarize the information provided in the articles to fit within the required format.
Here are 3-5 technical mitigations for the PoisonedRefresh and Dissecting a PHP web server rootkit:
* Implement secure coding practices: Ensure that all Apache and PHP components are updated with the latest security patches, including CVE-2025-53521.
* Use secure configuration options: Configure BIG-IP APM environments to use secure configuration options, such as SELinux and AppArmor, to limit privileges and prevent exploitation of vulnerabilities like CVE-2025-53521.
* Monitor for suspicious activity: Regularly monitor BIG-IP APM environments for suspicious activity, including unusual access patterns or changes in Apache process behavior, which could indicate the presence of a malware implant like PoisonedRefresh.
* Implement network segmentation: Segment the network to isolate BIG-IP APM environments from other systems and networks, reducing the attack surface and making it more difficult for attackers to exploit vulnerabilities like CVE-2025-53521.
* Use secure file system options: Configure the file system on BIG-IP APM servers to use secure options, such as encrypted storage or isolated file systems, to prevent malware implants from accessing sensitive data.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
26bd5b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ld•••••.so
bi•••••.pipe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
China ChopperChina Chopper
CVE-2025-53521CVE-2025-53521
Target & Sectors
CN
Incident Timeline
September 8, 2026
The second-stage malware, dubbed PoisonedRefresh by ESET, infects a modified Linux umount binary and embeds itself in BIG-IP upgrade images to survive device updates.
Click on any entity below to view its context and source!
infrastructure
Linux
SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Policy Manager environments.
Sophos tracks it as Linux/Agnt-IC.
The first stage, which Sophos found hidden inside a modified Linux
umount
binary, infects
/usr/sbin/httpd
, modifies SELinux configuration, and embeds itself in BIG-IP upgrade images to survive device updates.
The second-stage malware is a standalone Linux ELF binary that includes its own loader instead of relying on the normal Linux loader.
“This implant demonstrates how modern Linux malware can deliver familiar attacker capabilities through sophisticated delivery mechanisms.” concludes the report.
organisation
SophosLabs
SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Policy Manager environments.
organisation
ESET
SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Policy Manager environments.
organisation
Linux/Agnt-IC
Sophos tracks it as Linux/Agnt-IC.
organisation
Sophos
The first stage, which Sophos found hidden inside a modified Linux
umount
binary, infects
/usr/sbin/httpd
, modifies SELinux configuration, and embeds itself in BIG-IP upgrade images to survive device updates.
organisation
SELinux
The first stage, which Sophos found hidden inside a modified Linux
umount
binary, infects
/usr/sbin/httpd
, modifies SELinux configuration, and embeds itself in BIG-IP upgrade images to survive device updates.
organisation
CVE-2025
F5
associates
the related c05d5254 activity with BIG-IP APM systems affected by
CVE-2025-53521
, an exploited unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server.” reads the
report
published by SophosLabs.
organisation
CVE-2025-53521
The initial access vector is CVE-2025-53521, an unauthenticated remote code execution flaw in BIG-IP APM when an access policy is configured on a virtual server.
organisation
SHA-256
The SHA-256 hash of the analyzed sample is
26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9
.
organisation
APR
“The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows, suggesting it was developed for specific environments.
The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows, suggesting it was developed for specific environments.
organisation
BIG-IP APM
“The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows, suggesting it was developed for specific environments.
The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows, suggesting it was developed for specific environments.
organisation
The Shadowserver Foundation
The Shadowserver Foundation observed 795 internet-exposed endpoints vulnerable to this CVE at the time of disclosure.
infrastructure
795 exposed endpoints
The Shadowserver Foundation observed 795 internet-exposed endpoints vulnerable to this CVE at the time of disclosure.
organisation
F5
The vulnerability was previously classified as a denial-of-service issue before F5 confirmed it as an RCE.
organisation
TCP
“Alongside this web‑based access, the implant also creates a local UNIX domain socket and can redirect a connection into /bin/bash, enabling interactive access without opening a TCP listening port.”
organisation
CSS
This makes the response look like a successful CSS file request on a BIG-IP APM device.
organisation
Teams
Teams should also look for HTTP 201 responses with
Content-Type: text/css
when they do not match legitimate CSS or other asset requests.
organisation
Content-Type
Teams should also look for HTTP 201 responses with
Content-Type: text/css
when they do not match legitimate CSS or other asset requests.
organisation
ELF
“While the embedded PHP ultimately behaves like a traditional web shell, the surrounding infrastructure is considerably more advanced: custom ELF loading, early startup interception, APR-aware module monitoring, relocation patching, and memory-only payload delivery.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, PoisonedRefresh)
organisation
SecurityAffairs
“While the embedded PHP ultimately behaves like a traditional web shell, the surrounding infrastructure is considerably more advanced: custom ELF loading, early startup interception, APR-aware module monitoring, relocation patching, and memory-only payload delivery.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, PoisonedRefresh)
September 09, 2026
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM server memory.
Click on any entity below to view its context and source!
infrastructure
Linux
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
Pierluigi Paganini
September 09, 2026
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts.
tactic
T1014 - Rootkit
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
Pierluigi Paganini
September 09, 2026
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts.
tactic
T1584.004 - Server
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
Pierluigi Paganini
September 09, 2026
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts.
organisation
PHP
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
Pierluigi Paganini
September 09, 2026
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts.
organisation
APM Apache
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
Pierluigi Paganini
September 09, 2026
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts.
2026/09/09
The threat actors used a custom Linux fileless rootkit to inject PHP web shells into F5 BIG-IP APM servers.
Click on any entity below to view its context and source!
infrastructure
Linux
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory.
Protection and defense
Sophos detects this threat as
Linux/Agnt-IC.
SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components.
server‑side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache‑specific tradecraft.
Rather than starting from imports, we focused on:
Control‑flow pivots, especially around process startup
Runtime string decryption routines
Symbol resolution and hook installation logic
Use of Linux process introspection via
/proc
Transition points where encrypted or opaque data becomes plaintext and executable
This style of analysis is becoming increasingly important as Linux malware continues to move away from simple on-disk implants and toward custom loaders, runtime code generation, in-memory execution, and process manipulation.
Once decrypted at runtime, these strings reveal the implant’s true scope and intent:
/proc/self/exe
and
/proc/self/maps
, used for process self‑inspection
__libc_start_main
, the
libc
startup routine
apr_dso_load
and
apr_time_now
, APR functions inside Apache
libphp
, the PHP module targeted inside the Apache process
File and memory APIs such as
open
,
close
, and
mmap
Threading primitives like
pthread_create
and
pthread_detach
Individually, none of these strings are particularly exciting, but together they paint a picture of a sample that understands Linux process internals, Apache’s runtime, and PHP’s execution model.
For Linux server investigations, runtime string decryption, dynamic API resolution, and delayed revelation of configuration data are increasingly common in more capable Linux malware families.
Racing ‘main’ for execution
On Linux, most programs do not call
main
directly.
Ordinary Linux ELF binaries follow a well‑trodden path: the kernel loads the binary, the dynamic linker (
ld.so
) resolves dependencies, and then
libc’s
startup code prepares the environment and calls
main
.
In a conventional Linux executable,
_start
would normally proceed to
__libc_start_main
, which ultimately invokes
main()
.
In practical terms, this ‘bring your own loader’ approach provides the threat actor with several advantages:
It avoids the conventional dynamic-linker startup path, potentially reducing visibility from controls that rely on that sequence as a monitoring point
It gives the attacker precise control over when and how
libc
startup is intercepted
It gives a clean, single pivot point into the rest of the implant
From a defender’s perspective, it’s another reminder that relying on the normal loader path as an interception point is no longer sufficient for more capable Linux threats.
Linux exposes this information via
/proc/self/maps
, which lists all memory mappings along with their address ranges and backing files.
On 32‑bit Linux, socket operations are commonly multiplexed through the historical
socketcall
system call, which handles operations such as
socket
,
bind
,
listen
, and
accept
.
Conclusion
This implant demonstrates how modern Linux malware can deliver familiar attacker capabilities through sophisticated delivery mechanisms.
This sample is part of a broader class of Linux threats that rely less on obvious on-disk artifacts and more on runtime manipulation.
organisation
PoisonedRefresh
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory.
organisation
Linux/Agnt-IC
Protection and defense
Sophos detects this threat as
Linux/Agnt-IC.
organisation
SophosLabs
SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components.
organisation
BIG-IP Access Policy Management
SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components.
organisation
APM
SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components.
organisation
API
For Linux server investigations, runtime string decryption, dynamic API resolution, and delayed revelation of configuration data are increasingly common in more capable Linux malware families.
organisation
Ordinary Linux
Ordinary Linux ELF binaries follow a well‑trodden path: the kernel loads the binary, the dynamic linker (
ld.so
) resolves dependencies, and then
libc’s
startup code prepares the environment and calls
main
.
organisation
PHP
Dissecting a PHP web server rootkit.
organisation
ESET
Note: While engaged in this research, we became aware that researchers from ESET had
conducted
analysis of this malware, which they dubbed ‘PoisonedRefresh.’
organisation
CVE-2025
F5
associates
the related c05d5254 activity with BIG-IP APM systems affected by
CVE-2025-53521
, an exploited unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server.
organisation
JSP
Why this case matters
When defenders hear ‘web shell,’ they usually think of a small server‑side script, often written in PHP, JSP, or ASP, planted in a web‑accessible directory to provide persistent remote code execution through ordinary HTTP requests.
organisation
ASP
Why this case matters
When defenders hear ‘web shell,’ they usually think of a small server‑side script, often written in PHP, JSP, or ASP, planted in a web‑accessible directory to provide persistent remote code execution through ordinary HTTP requests.
organisation
SELinux
Our analysis suggests the sample discussed here represents a second-stage payload; during parallel analysis of a related
umount
sample, we noted a distinct installer/propagation component responsible for infecting
/usr/sbin/httpd
, persisting across BIG-IP upgrade images, modifying SELinux configurations, and deploying the payload analyzed in this article.
organisation
BIG-IP
Our analysis suggests the sample discussed here represents a second-stage payload; during parallel analysis of a related
umount
sample, we noted a distinct installer/propagation component responsible for infecting
/usr/sbin/httpd
, persisting across BIG-IP upgrade images, modifying SELinux configurations, and deploying the payload analyzed in this article.
organisation
AF_UNIX
As well as the HTTP‑driven web shell, the implant also establishes a local AF_UNIX socket at
/run/bigtlog.pipe
rather than exposing a traditional TCP listener.
organisation
TCP
Alongside this web‑based access, the implant also creates a local UNIX domain socket and can redirect a connection into
/bin/bash
, enabling interactive access without opening a TCP listening port.
organisation
CSS
PHP endpoints returning
HTTP 201
while claiming to be CSS (
Content-Type: text/css; charset=utf-8
).
organisation
Content-Type
The embedded PHP payload behaves like a classic web shell, with a few notable characteristics:
Reads raw request bytes from
php://input
Checks for a short magic prefix (BSOHAzPB) at the start of the request body
Decrypts the remainder using a small stream cipher
Executes the decrypted content via
eval
Returns
HTTP status 201
and sets
Content-Type: text/css; charset=utf-8
to blend into normal asset requests
The payload is templated, with key strings rewritten at runtime – further complicating static signature matching.
organisation
ELF
The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells.
organisation
0x5430
Notably, the malicious prefix size used by the infected
httpd
(0x5430) matches the size of the payload embedded within the
umount
sample, strongly suggesting that the latter is responsible for deploying the former.
organisation
CMS
Based on current public reporting and our analysis, the observed targeting centers on BIG-IP APM webtop environments rather than generic Apache/PHP or common CMS deployments.
organisation
UNIX
Instead, the implant intercepts the loading of specific PHP files and prepends a web shell to their in-memory representation at mmap() time
Process
‑
level compromise, not just app
‑
level:
the implant redirects selected
libc
and
libphp
function calls inside Apache worker processes, so every PHP‑based component executing within that process - plugins, scanners, local scripts - is running inside a manipulated runtime environment
Dual access channels:
attackers can use both an HTTP‑driven PHP payload and a local UNIX socket backdoor that gives them an interactive shell without a listening TCP port
The result is an access primitive that behaves like a web shell to the attacker, but is significantly harder to detect using file‑centric or PHP‑only detection alone.
organisation
Apache/PHP
Each of these techniques is relatively straightforward in isolation; the sophistication lies in how they are combined into a coherent, stable access mechanism targeted specifically at Apache/PHP deployments.
organisation
RWX
This is achieved by following the steps:
read /proc/self/maps -> find libphp -> mprotect RWX -> patch relocations -> mprotect RX
Reading
/proc/self/maps
is not inherently malicious.
organisation
wSLjN1beuR
In our sample, the request marker (BSOHAzPB) and web shell key (wSLjN1beuR) were patched into the PHP at runtime rather than stored directly in their final form.
organisation
apr_time_now
Delayed activation via apr_time_now
Rather than spawn threads or heavy routines during early startup, the implant uses its hook on
apr_time_now
as a delayed trigger.
organisation
Repeated POST
Repeated POST requests with consistent structure or unusual body sizes to CSS‑like PHP paths.
organisation
RX
Temporary changes to memory permissions on PHP module mappings (RWX followed by RX) around
libphp
.
data_breach
16 byte
The malware uses the RC4 stream cipher with a hardcoded 16-byte key:
TrswBWIl90Z5e38n
.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory.
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
Pierluigi Paganini
September 09, 2026
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts.
SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Policy Manager environments.
Sophos tracks it as Linux/Agnt-IC.
The first stage, which Sophos found hidden inside a modified Linux
umount
binary, infects
/usr/sbin/httpd
, modifies SELinux configuration, and embeds itself in BIG-IP upgrade images to survive device updates.
The second-stage malware is a standalone Linux ELF binary that includes its own loader instead of relying on the normal Linux loader.
“This implant demonstrates how modern Linux malware can deliver familiar attacker capabilities through sophisticated delivery mechanisms.” concludes the report.
Protection and defense
Sophos detects this threat as
Linux/Agnt-IC.
SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components.
server‑side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache‑specific tradecraft.
Rather than starting from imports, we focused on:
Control‑flow pivots, especially around process startup
Runtime string decryption routines
Symbol resolution and hook installation logic
Use of Linux process introspection via
/proc
Transition points where encrypted or opaque data becomes plaintext and executable
This style of analysis is becoming increasingly important as Linux malware continues to move away from simple on-disk implants and toward custom loaders, runtime code generation, in-memory execution, and process manipulation.
Once decrypted at runtime, these strings reveal the implant’s true scope and intent:
/proc/self/exe
and
/proc/self/maps
, used for process self‑inspection
__libc_start_main
, the
libc
startup routine
apr_dso_load
and
apr_time_now
, APR functions inside Apache
libphp
, the PHP module targeted inside the Apache process
File and memory APIs such as
open
,
close
, and
mmap
Threading primitives like
pthread_create
and
pthread_detach
Individually, none of these strings are particularly exciting, but together they paint a picture of a sample that understands Linux process internals, Apache’s runtime, and PHP’s execution model.
For Linux server investigations, runtime string decryption, dynamic API resolution, and delayed revelation of configuration data are increasingly common in more capable Linux malware families.
Racing ‘main’ for execution
On Linux, most programs do not call
main
directly.
Ordinary Linux ELF binaries follow a well‑trodden path: the kernel loads the binary, the dynamic linker (
ld.so
) resolves dependencies, and then
libc’s
startup code prepares the environment and calls
main
.
In a conventional Linux executable,
_start
would normally proceed to
__libc_start_main
, which ultimately invokes
main()
.
In practical terms, this ‘bring your own loader’ approach provides the threat actor with several advantages:
It avoids the conventional dynamic-linker startup path, potentially reducing visibility from controls that rely on that sequence as a monitoring point
It gives the attacker precise control over when and how
libc
startup is intercepted
It gives a clean, single pivot point into the rest of the implant
From a defender’s perspective, it’s another reminder that relying on the normal loader path as an interception point is no longer sufficient for more capable Linux threats.
Linux exposes this information via
/proc/self/maps
, which lists all memory mappings along with their address ranges and backing files.
On 32‑bit Linux, socket operations are commonly multiplexed through the historical
socketcall
system call, which handles operations such as
socket
,
bind
,
listen
, and
accept
.
Conclusion
This implant demonstrates how modern Linux malware can deliver familiar attacker capabilities through sophisticated delivery mechanisms.
This sample is part of a broader class of Linux threats that rely less on obvious on-disk artifacts and more on runtime manipulation.
Metrics
infrastructure
795
Exposed Endpoints
The Shadowserver Foundation observed 795 internet-exposed endpoints vulnerable to this CVE at the time of disclosure.
Metrics
data_breach
16
Byte
The malware uses the RC4 stream cipher with a hardcoded 16-byte key:
TrswBWIl90Z5e38n
.
Intelligence Sources
Security Affairs
2026-09-09
Sophos News
2026-09-07
Dissecting a PHP web server rootkit
Sophos News
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-10T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
38x
organisation
Identified Entity
PoisonedRefresh
entity
2x
timeline
Temporal Reference
September 09, 2026
date
2x
tactic
MITRE ATT&CK Technique
T1014 - Rootkit
technique
Contextual Telemetry
Context Block
11 METRICS
infrastructure
Affected Product
Linux
software
vulnerability
Exploited CVE
CVE-2025-53521
cve
tactic
Cyber Operation Type
Remote Code Execution
tactic
infrastructure
Exposed Endpoints
795
exposed endpoints
general metric
Http
201
http
target region
Target Country
China
country
malware
Malware Payload
China Chopper
tool
industry
Targeted Sector
Defense
sector
data breach
Byte
16
byte
general metric
Bit
32
bit
general metric
Behavior
1
behavior
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.