F5 BIG-IP APM PoisonedRefresh: Fileless PHP Web Shell After CVE-2025-53521 — Patch ≠ Clean

By George Bailey   Published: 09/14/26   Updated: 09/14/26   3 min read

Here’s the sentence that should stick: patching is not cleaning. Sophos detailed a fileless PHP web shell on compromised F5 BIG-IP APM boxes that can leave the on-disk scripts looking pristine — so a happy file-integrity scan can still be wrong.

If your APM was ever exposed to CVE-2025-53521, assume you need a compromise assessment, not just a green patch ticket.

What happened

SophosLabs (analysis published around Sep 7–8, 2026) described a Linux implant on compromised F5 BIG-IP Access Policy Manager (APM) appliances that injects a PHP web shell into memory without changing the scripts on disk. ESET previously called related samples PoisonedRefresh; Sophos tracks the family as Linux/Agnt-IC.

F5 ties related activity to appliances hit by CVE-2025-53521 — an unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server. (Originally disclosed as DoS in Oct 2025, later reclassified as critical RCE; in CISA KEV since March 2026.)

Why it matters

Fixing CVE-2025-53521 does not remove PoisonedRefresh. If the appliance was exploited before the patch, the shell can live in the running process — and possibly in httpd and upgrade media.

Tools that only hash the APM PHP scripts can report clean while the in-memory view still serves a web shell. That’s how these implants survive a “we patched” change window.

What to do first

Details

How it hides (short)

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.