A fileless rootkit dubbed PoisonedRefresh injects PHP web shells into the memory of compromised F5 BIG-IP APM appliances.
Attackers used an outdated F5 BIG-IP load balancer as an initial entry point to gain SSH access to a Linux…