A fileless rootkit dubbed PoisonedRefresh injects PHP web shells into the memory of compromised F5 BIG-IP APM appliances.
Attackers are hiding behind Google's trusted DoubleClick ad infrastructure to route victims toward a fileless malware loader that runs entirely…