Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: linux-rootkit (2 articles)Clear

Attackers plant a stealthy Linux rootkit on F5 BIG-IP access gateways

Researchers at Sophos and ESET found attackers breaching F5 BIG-IP APM access gateways and installing a stealthy Linux rootkit that ESET calls PoisonedRefresh. Rather than dropping a file on disk, it hides a web shell in memory, hooks into the Apache and PHP components, tampers with SELinux settings, and uses disguised requests to run commands while blending into normal traffic. Crucially, it persists across device upgrades, so patching the appliance alone does not remove it. The intrusions likely began by exploiting a critical remote code execution flaw that F5 had earlier downgraded to a mere denial-of-service issue, which may have led some organizations to deprioritize patching it.

Check
Treat internet-facing F5 BIG-IP APM devices as potentially compromised, patch the underlying remote code execution flaw, and hunt for in-memory web shells, Apache and PHP hooks, and altered SELinux settings.
Affected
Organizations running F5 BIG-IP APM access gateways, especially internet-facing ones on the vulnerable version; attackers install a memory-resident rootkit that survives upgrades and turns the gateway into a persistent, covert foothold.
Fix
Patch the F5 flaw, but because the rootkit survives upgrades, inspect and rebuild affected devices from known-good images, restrict management exposure, rotate credentials the gateway handled, and re-evaluate vendor DoS-only ratings.

Crime group uses AI to mass-hack servers and deploy a Linux rootkit backdoor

Cisco Talos detailed a financially motivated, Chinese-speaking group it tracks as UAT-10147 that breaks into internet-facing Windows and Linux web servers at scale and installs malware for data theft and search-engine-optimization fraud. The group weaves AI tools through its operations, from exploiting known vulnerabilities to generating payloads, and Talos even found AI-generated code comments left in the source of its Linux kernel rootkit. Its cross-platform implant, SPECTRE, offers credential theft, process injection, encrypted command-and-control, and driver-based bypassing of endpoint detection. Investigators also recovered prompt logs from AI coding assistants on the attackers' own machines, a concrete look at adversaries using the same agent tools defenders do.

Check
Patch internet-facing web servers promptly since the group exploits known flaws at scale, enforce protections that block unsigned driver loads, and deploy endpoint detection with kernel-level visibility on Windows and Linux.
Affected
Organizations running internet-facing IIS or Linux web servers with unpatched known vulnerabilities; the group gains access at scale, deploys a rootkit and cross-platform backdoor, disables endpoint detection, and steals credentials and data.
Fix
Prioritize patching exposed servers, enable hypervisor-protected code integrity to counter driver-based evasion, monitor east-west traffic from web servers to internal Linux hosts, and hunt for kernel rootkits and unexpected HTTPS beacons.