Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Hackers are leveraging a Linux rootkit to deploy fileless PHP web shells within F5 BIG-IP APM devices, bypassing traditional file-based detection.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Security researchers and news outlets report that hackers have successfully breached F5 BIG-IP APM devices to deploy a sophisticated Linux rootkit. This specific threat involves the use of a malware strain identified as PoisonedRefresh, which is designed to establish backdoors on F5 BIG-IP servers. According to coverage from BleepingComputer and CyberSecurityNews, the attack focuses on injecting PHP web shells into the compromised systems. These shells are characterized as being fileless, meaning they operate within the system's memory rather than residing as static files on the disk, which allows the attackers to maintain persistence while avoiding detection by standard security scans. Detailed technical analysis provided by Sophos involves the dissection of this PHP web server rootkit to understand its operational mechanics. Coverage from kobaran.com and gbhackers.com emphasizes that the PoisonedRefresh malware specifically hides inside Apache memory.
This memory-only approach ensures that while the malware is active and controlling the server, the F5 BIG-IP files themselves remain clean. The focus of these reports is the stealth nature of the injection process, as the rootkit enables the deployment of memory-only PHP web shells that do not leave traditional footprints in the file system. The context of this trend highlights a shift toward fileless malware targeting enterprise-grade networking and security hardware. By targeting F5 BIG-IP APM devices, attackers are focusing on critical infrastructure components that manage access and traffic. The use of a Linux rootkit suggests a high level of sophistication, as it allows for deep system integration and the ability to manipulate the operating environment. This matters because traditional antivirus and integrity checkers that look for modified files on the disk are unable to detect threats residing exclusively in the volatile memory of the Apache web server.
Future developments to monitor include further technical breakdowns of the PoisonedRefresh malware and official responses or patches from F5. Based on the current coverage from BleepingComputer and Sophos, the primary concern remains the ability of the rootkit to hide within memory. Security teams will likely be looking for indicators of compromise that do not rely on file hashes. The industry is now watching to see if other F5 BIG-IP devices have been similarly compromised and whether the attackers have expanded their toolkit beyond the current PHP web shell implementation.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.
Quick answers
What is PoisonedRefresh?
PoisonedRefresh is a malware strain used to backdoor F5 BIG-IP servers using memory-only PHP web shells.
How does the rootkit avoid detection?
It hides inside Apache memory, ensuring that the F5 BIG-IP files stay clean and avoid detection by file-based scans.
Which devices are being targeted?
The attacks are targeting F5 BIG-IP APM devices to deploy a Linux rootkit.
Coverage (7)
- F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News · 13h ago
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit BleepingComputer · 13h ago
- PoisonedRefresh Malware Hides Inside Apache Memory While F5 BIG-IP Files Stay Clean kobaran.com · 13h ago
- Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers CyberSecurityNews · 13h ago
- PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells gbhackers.com · 13h ago
- Dissecting a PHP web server rootkit Sophos · 13h ago
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit BleepingComputer · 13h ago
Topics
Related trends
Apple Releases iOS 26.6.2
Apple has rolled out iOS 26.6.2 for all users, prompting immediate attention across technology coverage.
Rumored 3D Mario Game Could Finally Be Revealed At Tomorrow’s Nintendo Direct
NVIDIA's DLSS 5 Adds Subtle Details To NBA 2K27, But Demands A Lot More Power
Sony RM-DP7 & RM-DP5 Monitors for the FX5, FX3, FX2, & FX30
Sony has launched the RM-DP7 and RM-DP5 remote camera control monitors for specific Cinema Line models.
Multiple amiibo Listings Have Apparently Been Spotted On GameStop's Internal Database
New amiibo figures for a Legend of Zelda: Ocarina of Time remake have been revealed following leaks from GameStop's internal database.
Game Awards Host Geoff Keighley And PlayStation Architect Mark Cerny Will Start Giving $2 Million To Young Game Designers Each Year
Game Awards host Geoff Keighley and PlayStation architect Mark Cerny launch the Nova Games Foundation with annual funding.