ThreatCluster

Advanced PHP Web Shell Exploits F5 BIG-IP Systems

First seen 7 Sep 2026, 20:02 UTC News.SophosGbhackersattack.mitre.orgCybersecuritynewsnvd.nist.gov 75

Article Content

Browse articles
ThreatCluster

A sophisticated Linux implant targeting F5 BIG-IP Access Policy Management (APM) environments has been identified, exploiting CVE-2025-53521, an unauthenticated remote code execution vulnerability. This malware, referred to as 'PoisonedRefresh,' employs advanced techniques like function hooking and memory-only web shell deployment to maintain persistent access. The attack specifically affects systems using Apache and PHP components, particularly in BIG-IP APM setups. Researchers have noted that the malware's installation process is designed to persist across system upgrades and modifications. The implant operates by injecting a PHP web shell into memory, avoiding detection by traditional file-based defenses. F5 has confirmed the exploitation of the vulnerability and provided guidance for remediation. Organizations using affected versions of BIG-IP APM are urged to follow F5's security recommendations to mitigate risks.

Key Points: • The malware exploits CVE-2025-53521 affecting F5 BIG-IP APM systems. • It uses advanced techniques for stealth, including memory-only web shell deployment. • F5 has confirmed active exploitation and issued remediation guidance.

Ask AI about this cluster

Timeline

2025-10-15
CVE-2025-53521 published
An unauthenticated remote code execution vulnerability in F5 BIG-IP APM was disclosed.
Gbhackers
2026-03-27
CVE-2025-53521 added to CISA KEV
CISA listed the vulnerability as actively exploited in the wild.
Gbhackers
Recent
Malware analysis reveals advanced techniques
SophosLabs detailed the malware's use of function hooking and memory-only web shells.
News.Sophos