Tech News
← Home  ·  All topics

Linux Rootkit

1 GoKawiil brief on this topic

Sophos finds fileless Linux rootkit hitting F5 BIG-IP APM devices

Sophos researchers detailed a second-stage Linux rootkit infecting F5 BIG-IP APM systems, likely delivered after attackers exploited the critical CVE-2025-53521 remote code execution flaw. The malware infects Apache's httpd process, hooks internal functions to intercept PHP file loading, and injects a web shell into memory rather than writing files to disk, while also altering SELinux settings and persisting through firmware upgrades. ESET separately analyzed the same threat under the name PoisonedRefresh.