Attackers plant a stealthy Linux rootkit on F5 BIG-IP access gateways
Researchers at Sophos and ESET found attackers breaching F5 BIG-IP APM access gateways and installing a stealthy Linux rootkit that ESET calls PoisonedRefresh. Rather than dropping a file on disk, it hides a web shell in memory, hooks into the Apache and PHP components, tampers with SELinux settings, and uses disguised requests to run commands while blending into normal traffic. Crucially, it persists across device upgrades, so patching the appliance alone does not remove it. The intrusions likely began by exploiting a critical remote code execution flaw that F5 had earlier downgraded to a mere denial-of-service issue, which may have led some organizations to deprioritize patching it.
- Check
- Treat internet-facing F5 BIG-IP APM devices as potentially compromised, patch the underlying remote code execution flaw, and hunt for in-memory web shells, Apache and PHP hooks, and altered SELinux settings.
- Affected
- Organizations running F5 BIG-IP APM access gateways, especially internet-facing ones on the vulnerable version; attackers install a memory-resident rootkit that survives upgrades and turns the gateway into a persistent, covert foothold.
- Fix
- Patch the F5 flaw, but because the rootkit survives upgrades, inspect and rebuild affected devices from known-good images, restrict management exposure, rotate credentials the gateway handled, and re-evaluate vendor DoS-only ratings.