{"id":1485,"date":"2026-09-09T12:03:45","date_gmt":"2026-09-09T06:33:45","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1485"},"modified":"2026-09-10T09:14:38","modified_gmt":"2026-09-10T03:44:38","slug":"f5-big-ip-apm-rootkit","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/","title":{"rendered":"F5 BIG-IP APM Rootkit: How PoisonedRefresh Hides a Web Shell in Memory"},"content":{"rendered":"<p>Attackers targeting F5 BIG-IP APM environments have deployed a Linux rootkit that injects a PHP web shell directly into process memory. The technique leaves the targeted PHP files unchanged on disk, making conventional file-based web shell checks less effective.<\/p>\n<p>Sophos analyzed the implant, while ESET independently tracks the malware as PoisonedRefresh. The malware appears to be a second-stage payload associated with compromised BIG-IP APM environments. Related activity is associated with CVE-2025-53521, an actively exploited BIG-IP APM remote code execution vulnerability. However, the available research does not establish CVE-2025-53521 as the initial-access vector for every analyzed PoisonedRefresh infection.<\/p>\n<p>That distinction matters. CVE-2025-53521 can result in unauthenticated remote code execution, while PoisonedRefresh appears to be a second-stage payload likely deployed after exploitation. However, the available research does not establish CVE-2025-53521 as the deployment path for every PoisonedRefresh infection or document alternative initial-access vectors.<\/p>\n<h2>F5 BIG-IP APM Rootkit at a Glance<\/h2>\n<table style=\"font-weight: 400; width: 99.367%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"11\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Information<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Vulnerability<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVE-2025-53521<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Affected product<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">F5 BIG-IP Access Policy Manager<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Vulnerability type<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Stack-based buffer overflow; potential impact: remote code execution<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVSS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">9.8 CVSS v3.1 \/ 9.3 CVSS v4.0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Exploitation status<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Active exploitation confirmed<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Malware name<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">PoisonedRefresh\u00a0by ESET; Linux\/Agnt-IC detection by Sophos<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Rootkit target<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">BIG-IP APM environments using Apache and PHP components<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Distinctive behavior<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">In-memory PHP web shell injection<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CISA KEV<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Added March 27, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 33.9426%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Fixed releases for affected branches<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 87.4674%;\" data-celllook=\"0\"><span data-contrast=\"auto\">15.1.10.8, 16.1.6.1, 17.1.3, 17.5.1.3, and 21.0.0.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>CVE-2025-53521 affects BIG-IP APM when an access policy is configured on a virtual server. F5 initially described the issue differently before later confirming that specific malicious traffic could result in unauthenticated RCE.<\/p>\n<h2>How PoisonedRefresh Makes Clean PHP Files Execute Malicious Code<\/h2>\n<p>The distinctive part of PoisonedRefresh is not simply that it provides a web shell. It changes what Apache&#8217;s PHP runtime sees when selected files are loaded.<\/p>\n<p>Sophos found that the second-stage implant hooks <code>__libc_start_main<\/code>. It also hooks the Apache Portable Runtime function <code>apr_dso_load<\/code> to detect when Apache loads PHP components as part of its PHP-injection mechanism.<\/p>\n<p>From there, the malware manipulates memory behavior inside <code>libphp<\/code>. This lets it alter the in-memory representation of selected BIG-IP APM webtop scripts, including:<\/p>\n<ul>\n<li><code>apm_css.php3<\/code><\/li>\n<li><code>full_wt.php3<\/code><\/li>\n<li><code>webtop_popup_css.php3<\/code><\/li>\n<\/ul>\n<p>The PHP files stored on disk can therefore remain unchanged while Apache workers process malicious content injected into memory.<\/p>\n<p>Searching the filesystem specifically for a malicious <code>.php<\/code> web shell may miss this payload because the targeted PHP files remain unchanged while malicious content is injected into their in-memory representation.<\/p>\n<h3>Magic Requests Trigger the Hidden PHP Web Shell<\/h3>\n<p>The injected code waits for specially formatted HTTP requests.<\/p>\n<p>When a matching request arrives, the web shell processes attacker-controlled data and executes the supplied PHP through <code>eval<\/code>. Responses can use <code>HTTP 201<\/code> with a <code>text\/css<\/code> content type, helping the command channel resemble traffic associated with the targeted webtop resources.<\/p>\n<p>This behavior gives defenders network and application-layer indicators even when the malicious PHP itself cannot be found on disk.<\/p>\n<h2>PoisonedRefresh Adds a Local Shell Beyond the Web Backdoor<\/h2>\n<p>Sophos also identified another access mechanism at <code>\/run\/bigtlog.pipe<\/code>.<\/p>\n<p>The implant creates this path as a local UNIX-domain socket. After its authentication condition is satisfied, it can redirect standard input, output, and error to <code>\/bin\/bash<\/code>, providing interactive shell access.<\/p>\n<p>Unlike a conventional TCP listener, the socket is local to the compromised system. An attacker would therefore need another way to interact with it. Sophos had not identified that component in the analyzed evidence.<\/p>\n<p>The distinction is important because the socket demonstrates an additional malware capability without proving how attackers accessed that capability during every intrusion.<\/p>\n<h2>The Rootkit Reaches Beyond a Memory-Only PHP Payload<\/h2>\n<p>Calling PoisonedRefresh purely \u201cfileless\u201d can also obscure part of the attack.<\/p>\n<p>The PHP web shell is injected into memory, while Sophos found that a distinct installer or propagation component infected <code>\/usr\/sbin\/httpd<\/code>, modified SELinux configurations, and established persistence across BIG-IP upgrade images.<\/p>\n<p>F5 separately published compromise indicators in advisory <a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000160486?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=f5_big_ip_apm_rootkit\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">K000160486<\/a>. These broader F5 indicators should not automatically be attributed to PoisonedRefresh unless evidence links them to the same intrusion.<\/p>\n<p>Therefore, defenders should combine runtime and memory investigation with checks for modified system files, SELinux configuration changes, and other persistence artifacts.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/5-Ways-Hexnode-Strengthens-Your-Incident-Response-Plan-1024x535-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>5 Ways Hexnode Strengthens Your Incident Response Plan<\/h4><p>Learn how threat investigation, remediation actions, and UEM controls can strengthen enterprise incident response workflows.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/5-ways-hexnode-strengthens-your-incident-response-plan\/\" aria-label=\"5 Ways Hexnode Strengthens Your Incident Response Plan\"><\/a><\/div><\/div><\/div>\n<h2>What Should BIG-IP APM Administrators Investigate?<\/h2>\n<p>Organizations currently running vulnerable BIG-IP APM releases, or appliances that were upgraded after previously running a vulnerable release, should follow F5&#8217;s official remediation and compromise-assessment guidance.<\/p>\n<p>Useful investigation leads from the available research include:<\/p>\n<ul>\n<li>Apache workers reading <code>\/proc\/self\/maps<\/code><\/li>\n<li>memory-protection changes involving libphp<\/li>\n<li>creation of <code>\/run\/bigtlog.pipe<\/code><\/li>\n<li><code>\/bin\/bash<\/code> launches associated with Apache or the suspected implant activity<\/li>\n<li>unusual POST requests to the targeted <code>.php3<\/code> endpoints<\/li>\n<li>responses combining <code>HTTP 201<\/code> with a <code>text\/css<\/code> content type<\/li>\n<\/ul>\n<p>These indicators should be correlated with other evidence rather than treated individually as definitive proof of compromise.<\/p>\n<p>For appliances that ran vulnerable releases, applying the fix should be paired with compromise assessment. Government advisories recommend examining potentially affected systems, including appliances later upgraded from vulnerable releases, while distinguishing those systems from clean installations of fixed software.<\/p>\n<h2>Where Hexnode Fits After an Edge-Appliance Compromise<\/h2>\n<p>The F5 BIG-IP APM rootkit runs on the BIG-IP appliance itself, so endpoint security tools should not be presented as direct PoisonedRefresh detection or remediation mechanisms.<\/p>\n<p>However, an edge-device compromise can justify expanding an investigation to administrator workstations and other managed endpoints when evidence indicates activity beyond the appliance.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Why-XDR-IS-stronger-thumbnail\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            See how combining endpoint management with extended detection and response can improve security visibility, investigation, and incident response.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h3>Investigate Suspicious Endpoint Activity with Hexnode XDR<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> protects supported Windows and macOS endpoints; it does not install on or directly protect the Linux-based BIG-IP appliance discussed in this incident. If responders identify suspicious activity on managed Windows or macOS endpoints connected to the broader investigation, they can use Hexnode XDR&#8217;s threat-hunting and query-based investigation capabilities.<\/p>\n<p>Security teams can use these capabilities to investigate endpoint activity and respond to confirmed endpoint threats. Current Hexnode XDR capabilities also include device isolation, process termination and file quarantine. These actions apply to supported endpoints, not the compromised BIG-IP appliance itself.<\/p>\n<p>Therefore, Hexnode XDR complements the wider investigation but does not replace F5-specific appliance forensics or remediation.<\/p>\n<h3>Maintain Security Posture on Administrative Endpoints with Hexnode UEM<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can support a separate defensive layer around workstations used by IT and security administrators.<\/p>\n<p>Administrators can define compliance policies across managed platforms and identify devices that fail configured requirements. Hexnode UEM also supports remote custom-script execution on managed Windows, macOS, and Linux devices, subject to documented platform requirements.<\/p>\n<p>These controls can help organizations maintain compliance and manage administrator endpoints during a broader incident. They do not patch <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2025-53521?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=f5_big_ip_apm_rootkit\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2025-53521<\/a> or remove PoisonedRefresh from a BIG-IP appliance.<\/p>\n<h3>PoisonedRefresh Makes Runtime Integrity Part of BIG-IP Incident Response<\/h3>\n<p>The F5 BIG-IP APM rootkit demonstrates why checking PHP files alone cannot rule out a web shell.<\/p>\n<p>PoisonedRefresh changes the runtime view of legitimate PHP content while leaving the corresponding PHP files on disk untouched.<\/p>\n<p>A separate installer or propagation component infected <code>\/usr\/sbin\/httpd<\/code>, while the second-stage implant creates an authentication-protected local UNIX-domain socket capable of launching an interactive Bash shell.<\/p>\n<p>Organizations should apply F5&#8217;s fixes to vulnerable BIG-IP APM deployments and assess appliances that previously ran vulnerable releases for evidence of compromise.<\/p>\n<p>Endpoint investigation can then extend beyond the appliance when incident evidence warrants it. Hexnode XDR can support investigation and containment on managed Windows and macOS endpoints, while Hexnode UEM can help administrators define compliance requirements and identify non-compliant administrator devices. Neither replaces BIG-IP-specific remediation.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Extend Threat Investigation to Your Endpoints<\/h5><p>Investigate suspicious endpoint activity and respond to confirmed threats across managed Windows and macOS environments with Hexnode XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your 14-Day Free Trial<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Attackers targeting F5 BIG-IP APM environments have deployed a Linux rootkit that injects a PHP&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1524,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,20],"class_list":["post-1485","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-network-and-vpn","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>F5 BIG-IP APM Rootkit: PoisonedRefresh Explained<\/title>\n<meta name=\"description\" content=\"F5 BIG-IP APM rootkit PoisonedRefresh injects a web shell into memory. Learn how it works, what to investigate, and how to respond.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"F5 BIG-IP APM Rootkit: PoisonedRefresh Explained\" \/>\n<meta property=\"og:description\" content=\"F5 BIG-IP APM rootkit PoisonedRefresh injects a web shell into memory. Learn how it works, what to investigate, and how to respond.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-09T06:33:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-10T03:44:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"F5 BIG-IP APM Rootkit: How PoisonedRefresh Hides a Web Shell in Memory\",\"datePublished\":\"2026-09-09T06:33:45+00:00\",\"dateModified\":\"2026-09-10T03:44:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/\"},\"wordCount\":1196,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp\",\"articleSection\":[\"Malware\",\"Network and VPN\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/\",\"name\":\"F5 BIG-IP APM Rootkit: PoisonedRefresh Explained\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp\",\"datePublished\":\"2026-09-09T06:33:45+00:00\",\"dateModified\":\"2026-09-10T03:44:38+00:00\",\"description\":\"F5 BIG-IP APM rootkit PoisonedRefresh injects a web shell into memory. Learn how it works, what to investigate, and how to respond.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"F5 BIG-IP APM Rootkit How PoisonedRefresh Hides a Web Shell in Memory\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/f5-big-ip-apm-rootkit\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"F5 BIG-IP APM Rootkit: How PoisonedRefresh Hides a Web Shell in Memory\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"F5 BIG-IP APM Rootkit: PoisonedRefresh Explained","description":"F5 BIG-IP APM rootkit PoisonedRefresh injects a web shell into memory. Learn how it works, what to investigate, and how to respond.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/","og_locale":"en_US","og_type":"article","og_title":"F5 BIG-IP APM Rootkit: PoisonedRefresh Explained","og_description":"F5 BIG-IP APM rootkit PoisonedRefresh injects a web shell into memory. Learn how it works, what to investigate, and how to respond.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-09T06:33:45+00:00","article_modified_time":"2026-09-10T03:44:38+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"F5 BIG-IP APM Rootkit: How PoisonedRefresh Hides a Web Shell in Memory","datePublished":"2026-09-09T06:33:45+00:00","dateModified":"2026-09-10T03:44:38+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/"},"wordCount":1196,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp","articleSection":["Malware","Network and VPN"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/","url":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/","name":"F5 BIG-IP APM Rootkit: PoisonedRefresh Explained","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp","datePublished":"2026-09-09T06:33:45+00:00","dateModified":"2026-09-10T03:44:38+00:00","description":"F5 BIG-IP APM rootkit PoisonedRefresh injects a web shell into memory. Learn how it works, what to investigate, and how to respond.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/F5-BIG-IP-APM-Rootkit-How-PoisonedRefresh-Hides-a-Web-Shell-in-Memory.jpeg?format=webp","width":1340,"height":754,"caption":"F5 BIG-IP APM Rootkit How PoisonedRefresh Hides a Web Shell in Memory"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/f5-big-ip-apm-rootkit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"F5 BIG-IP APM Rootkit: How PoisonedRefresh Hides a Web Shell in Memory"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1485"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1485\/revisions"}],"predecessor-version":[{"id":1502,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1485\/revisions\/1502"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1524"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}