Advanced PHP Web Shell Exploits F5 BIG-IP Systems
Article Content
A sophisticated Linux implant targeting F5 BIG-IP Access Policy Management (APM) environments has been identified, exploiting CVE-2025-53521, an unauthenticated remote code execution vulnerability. This malware, referred to as 'PoisonedRefresh,' employs advanced techniques like function hooking and memory-only web shell deployment to maintain persistent access. The attack specifically affects systems using Apache and PHP components, particularly in BIG-IP APM setups. Researchers have noted that the malware's installation process is designed to persist across system upgrades and modifications. The implant operates by injecting a PHP web shell into memory, avoiding detection by traditional file-based defenses. F5 has confirmed the exploitation of the vulnerability and provided guidance for remediation. Organizations using affected versions of BIG-IP APM are urged to follow F5's security recommendations to mitigate risks.
Key Points: • The malware exploits CVE-2025-53521 affecting F5 BIG-IP APM systems. • It uses advanced techniques for stealth, including memory-only web shell deployment. • F5 has confirmed active exploitation and issued remediation guidance.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.