Executive Summary
Sophos X-Ops has identified a sophisticated attack campaign targeting F5 BIG-IP APM systems through CVE-2025-53521, a critical unauthenticated RCE. The attackers deploy a multi-stage Linux implant termed 'PoisonedRefresh' that achieves persistence across system upgrades and avoids traditional detection by modifying the host application's memory during execution.
Technically, the malware functions as an in-process rootkit. It intercepts the HTTP process startup, monitors for the loading of the PHP module, and hooks the 'mmap' function to inject a fileless PHP webshell directly into memory when specific scripts are read. This means the on-disk legitimate PHP files remain unchanged, frustrating standard File Integrity Monitoring (FIM). In addition to the web-based access, the implant creates a local UNIX domain socket backdoor for interactive shell access.
This campaign targets organizations utilizing F5 BIG-IP for access management, primarily in government and critical infrastructure. The combination of memory-only payloads, custom ELF loading, and persistence within upgrade images highlights a high level of operational sophistication and posing a severe risk for long-term espionage.
