A fileless rootkit dubbed PoisonedRefresh injects PHP web shells into the memory of compromised F5 BIG-IP APM appliances.