PoisonedRefresh Malware Exploits BIG‑IP APM Flaw to Install Memory‑Only PHP Web Shells
A sophisticated Linux‑based implant dubbed "PoisonedRefresh" has been observed infiltrating F5 BIG‑IP Access Policy Management (APM) devices by leveraging an unauthenticated remote‑code execution vulnerability identified as CVE‑2025‑53521. The malware establishes a memory‑only PHP web shell, allowing attackers to maintain persistent, stealthy access to compromised networks.
The exploit chain begins with the CVE‑2025‑53521 flaw, which permits execution of arbitrary code when an APM access policy is configured. Once the vulnerability is triggered, the attacker uploads a lightweight Linux payload that resides solely in RAM, avoiding disk writes that could be detected by traditional file‑integrity tools. The payload then spawns a PHP web shell, also memory‑resident, granting the threat actor a familiar web‑based command interface.
Security researchers at GBHackers first reported the activity, noting that the backdoor’s design mirrors previous APT‑style operations that prioritize evasion. By keeping both the implant and the web shell in memory, the malware sidesteps many endpoint detection and response (EDR) solutions that rely on file‑system monitoring. The PHP shell, despite its simplicity, provides a versatile foothold for further lateral movement, data exfiltration, or deployment of additional tools.
F5 Networks, the vendor of BIG‑IP appliances, has long warned customers about the critical nature of the APM module, which sits at the junction of authentication and application delivery. While the company regularly releases firmware updates to address security flaws, the rapid emergence of CVE‑2025‑53521 underscores the pressure on administrators to apply patches promptly. Organizations that have not yet updated to the latest secure version remain vulnerable to the PoisonedRefresh implant.
Industry analysts stress that the incident highlights a broader trend: attackers are increasingly targeting infrastructure components that sit between users and internal services. By compromising a load balancer or access policy manager, threat actors can intercept traffic, manipulate authentication flows, and gain a privileged position within corporate networks.
Mitigation guidance recommends immediate verification of firmware versions on all BIG‑IP APM devices, followed by deployment of the vendor‑issued patch for CVE‑2025‑53521. Administrators should also audit access policies for unnecessary exposure, enforce strict network segmentation, and enable logging of anomalous command execution. Deploying memory‑analysis tools or behavioral EDR solutions can help detect the presence of in‑memory web shells.
Going forward, security teams are advised to monitor threat‑intel feeds for indicators of compromise associated with the PoisonedRefresh malware, such as specific network traffic patterns or the unique PHP shell payload. Continued collaboration between vendors, researchers, and affected organizations will be essential to curb the impact of this sophisticated attack vector and to harden critical application delivery infrastructure against future exploits.
Comments (0)
Be the first to comment.
Join the discussion