PoisonedRefresh Rootkit Exploiting F5 BIG-IP APM CVE-2025-53521
Score: 9/10

PoisonedRefresh Rootkit Exploiting F5 BIG-IP APM CVE-2025-53521

Cluster c05d5254 utilizes the PoisonedRefresh rootkit to inject fileless PHP web shells into F5 BIG-IP APM memory via CVE-2025-53521 exploitation.

Executive Summary

A sophisticated Linux rootkit identified as PoisonedRefresh (or Linux/Agnt-IC) is targeting F5 BIG-IP APM appliances by exploiting CVE-2025-53521, a critical unauthenticated remote code execution vulnerability. While no vendor has formally attributed the activity, the cluster is tracked as c05d5254. The infection involves a two-stage process where a malicious installer modifies host binaries and upgrade images to ensure long-term persistence across device updates.

Technically, the malware operates by hooking Apache runtime functions to inject a fileless PHP web shell directly into process memory, leaving the on-disk files untouched and invisible to standard integrity monitors. It establishes a hidden interactive shell through a local UNIX domain socket and uses RC4-encrypted C2 communication disguised as legitimate CSS traffic. The vulnerability was originally misclassified as a denial-of-service risk, creating a significant exposure window for organizations that deprioritized patching.

This threat is highly critical due to the malware's ability to survive firmware upgrades and its specific design for BIG-IP APM internals. Over 14,000 instances were exposed in early 2026, and despite high patch adoption, hundreds remain vulnerable. Compromised organizations must perform memory forensics and rebuild configurations from scratch, as standard patching does not remove the persistent implant.

Key Details

Threat Name

PoisonedRefresh Rootkit

Affects

F5 BIG-IP APM 15.1.0 through 15.1.10, F5 BIG-IP APM 16.1.0 through 16.1.6, F5 BIG-IP APM 17.1.0 through 17.1.2, F5 BIG-IP APM 17.5.0 through 17.5.1

Adversary

c05d5254

Malware/Tools

PoisonedRefresh, Metasploit

Report Score

9out of 10
Quality Score
Excellent
IOC Quality7
TTP Details9
Detection Guidance8
Enterprise Relevance9
Clarity & Structure10
Technical Depth9

Sources