Skip to content

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory

Gbhackers Mayura Kathir September 7, 2026

A sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with exploitation of CVE-2025-53521, an unauthenticated remote code execution flaw affecting BIG-IP APM when an access policy is configured on a virtual server. F5 has confirmed exploitation of the vulnerability and links the related compromise activity […]

Extracted Entities

Attack Types (1)

Companies (1)

CWE Weaknesses (1)

Malware (1)

Platforms (2)