PoisonedRefresh Exploits F5 BIG-IP via Memory-Injected Rootkit
Score: 9/10

PoisonedRefresh Exploits F5 BIG-IP via Memory-Injected Rootkit

An advanced threat actor, PoisonedRefresh, is exploiting CVE-2025-53521 in F5 BIG-IP systems to deploy a sophisticated Linux rootkit that injects in-memory PHP webshells.

Executive Summary

Sophos X-Ops has identified a sophisticated attack campaign targeting F5 BIG-IP APM systems through CVE-2025-53521, a critical unauthenticated RCE. The attackers deploy a multi-stage Linux implant termed 'PoisonedRefresh' that achieves persistence across system upgrades and avoids traditional detection by modifying the host application's memory during execution.

Technically, the malware functions as an in-process rootkit. It intercepts the HTTP process startup, monitors for the loading of the PHP module, and hooks the 'mmap' function to inject a fileless PHP webshell directly into memory when specific scripts are read. This means the on-disk legitimate PHP files remain unchanged, frustrating standard File Integrity Monitoring (FIM). In addition to the web-based access, the implant creates a local UNIX domain socket backdoor for interactive shell access.

This campaign targets organizations utilizing F5 BIG-IP for access management, primarily in government and critical infrastructure. The combination of memory-only payloads, custom ELF loading, and persistence within upgrade images highlights a high level of operational sophistication and posing a severe risk for long-term espionage.

Key Details

Threat Name

PoisonedRefresh

Affects

BIG-IP APM

Adversary

PoisonedRefresh

Malware/Tools

PoisonedRefresh, Agnt-IC, umount, China Chopper

Report Score

9out of 10
Quality Score
Excellent
IOC Quality7
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth10

Sources