Executive Summary
A sophisticated Linux rootkit identified as PoisonedRefresh (or Linux/Agnt-IC) is targeting F5 BIG-IP APM appliances by exploiting CVE-2025-53521, a critical unauthenticated remote code execution vulnerability. While no vendor has formally attributed the activity, the cluster is tracked as c05d5254. The infection involves a two-stage process where a malicious installer modifies host binaries and upgrade images to ensure long-term persistence across device updates.
Technically, the malware operates by hooking Apache runtime functions to inject a fileless PHP web shell directly into process memory, leaving the on-disk files untouched and invisible to standard integrity monitors. It establishes a hidden interactive shell through a local UNIX domain socket and uses RC4-encrypted C2 communication disguised as legitimate CSS traffic. The vulnerability was originally misclassified as a denial-of-service risk, creating a significant exposure window for organizations that deprioritized patching.
This threat is highly critical due to the malware's ability to survive firmware upgrades and its specific design for BIG-IP APM internals. Over 14,000 instances were exposed in early 2026, and despite high patch adoption, hundreds remain vulnerable. Compromised organizations must perform memory forensics and rebuild configurations from scratch, as standard patching does not remove the persistent implant.
Key Details
Threat Name
PoisonedRefresh Rootkit
Affects
F5 BIG-IP APM 15.1.0 through 15.1.10, F5 BIG-IP APM 16.1.0 through 16.1.6, F5 BIG-IP APM 17.1.0 through 17.1.2, F5 BIG-IP APM 17.5.0 through 17.5.1
Adversary
c05d5254
Malware/Tools
PoisonedRefresh, Metasploit
