PULSE the living trend engine
↑ Rising Technology

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Hackers are leveraging a Linux rootkit to deploy fileless PHP web shells within F5 BIG-IP APM devices, bypassing traditional file-based detection.

6sources
7articles
4velocity
+53%since first seen
2h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

Security researchers and news outlets report that hackers have successfully breached F5 BIG-IP APM devices to deploy a sophisticated Linux rootkit. This specific threat involves the use of a malware strain identified as PoisonedRefresh, which is designed to establish backdoors on F5 BIG-IP servers. According to coverage from BleepingComputer and CyberSecurityNews, the attack focuses on injecting PHP web shells into the compromised systems. These shells are characterized as being fileless, meaning they operate within the system's memory rather than residing as static files on the disk, which allows the attackers to maintain persistence while avoiding detection by standard security scans. Detailed technical analysis provided by Sophos involves the dissection of this PHP web server rootkit to understand its operational mechanics. Coverage from kobaran.com and gbhackers.com emphasizes that the PoisonedRefresh malware specifically hides inside Apache memory.

This memory-only approach ensures that while the malware is active and controlling the server, the F5 BIG-IP files themselves remain clean. The focus of these reports is the stealth nature of the injection process, as the rootkit enables the deployment of memory-only PHP web shells that do not leave traditional footprints in the file system. The context of this trend highlights a shift toward fileless malware targeting enterprise-grade networking and security hardware. By targeting F5 BIG-IP APM devices, attackers are focusing on critical infrastructure components that manage access and traffic. The use of a Linux rootkit suggests a high level of sophistication, as it allows for deep system integration and the ability to manipulate the operating environment. This matters because traditional antivirus and integrity checkers that look for modified files on the disk are unable to detect threats residing exclusively in the volatile memory of the Apache web server.

Future developments to monitor include further technical breakdowns of the PoisonedRefresh malware and official responses or patches from F5. Based on the current coverage from BleepingComputer and Sophos, the primary concern remains the ability of the rootkit to hide within memory. Security teams will likely be looking for indicators of compromise that do not rely on file hashes. The industry is now watching to see if other F5 BIG-IP devices have been similarly compromised and whether the attackers have expanded their toolkit beyond the current PHP web shell implementation.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.

Quick answers

What is PoisonedRefresh?

PoisonedRefresh is a malware strain used to backdoor F5 BIG-IP servers using memory-only PHP web shells.

How does the rootkit avoid detection?

It hides inside Apache memory, ensuring that the F5 BIG-IP files stay clean and avoid detection by file-based scans.

Which devices are being targeted?

The attacks are targeting F5 BIG-IP APM devices to deploy a Linux rootkit.

Coverage (7)

Topics

Related trends

▲ Peaking Technology

Apple Releases iOS 26.6.2

Apple has rolled out iOS 26.6.2 for all users, prompting immediate attention across technology coverage.

1 sources 1 articles v 0 39m ago
\n \n \n \n \n \n \n