Back to all lessons
Awareness Lessons
last month

Linux Rootkit Exploits Unpatched F5 BIG-IP APM Flaw to Achieve Fileless Persistence

The PoisonedRefresh rootkit exploits CVE-2025-53521, a critical vulnerability in F5 BIG-IP APM devices that had not been patched on affected systems. By injecting a fileless web shell directly into memory and infecting the Apache httpd binary, attackers evade traditional disk-based detection tools entirely. The malware further entrenches itself by tampering with SELinux configurations — a mandatory access control mechanism — effectively disabling a key defensive layer. This attack illustrates how unpatched network appliances, especially those exposed to the internet, represent high-value entry points that can be compromised with devastating stealth. Organizations that rely solely on file-based antivirus or lack memory-level inspection are particularly blind to this class of threat.

Tactical Insight

Immediate Actions

  • Apply F5's official patch or mitigation for CVE-2025-53521 immediately across all BIG-IP APM instances.
  • Audit and restore SELinux configurations to enforcing mode on all affected and potentially exposed devices.
  • Isolate internet-facing F5 BIG-IP appliances behind strict firewall rules until patching is confirmed complete.

Detection Measures

  • Deploy runtime memory integrity monitoring and behavioral analysis tools capable of detecting fileless malware and in-memory web shells.
  • Monitor for unexpected modifications to critical binaries such as Apache httpd using file integrity monitoring (FIM) tools.
  • Centralize and alert on SELinux policy change events within your SIEM to catch unauthorized configuration tampering.

Long-Term Improvements

  • Maintain a continuously updated inventory of all network appliances and their patch status, prioritizing internet-facing assets.
  • Establish an emergency patching SLA (e.g., 24–72 hours) for critical CVEs affecting perimeter or load-balancing infrastructure.
  • Implement network segmentation to limit lateral movement opportunities if a BIG-IP or similar appliance is compromised.