Threat IntelligenceStealthy Linux rootkit hides inside F5 BIG-IP devices and runs entirely from memory
Researchers say the implant, tracked by ESET as PoisonedRefresh, hooks Apache to slip a hidden web shell into legitimate PHP files without ever touching disk.