Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Linux rootkit was likely deployed after exploiting CVE-2025-53521, a critical remote-code-execution flaw affecting F5 BIG-IP APM that F5 Networks reclassified from a DoS problem in March. | ESET identifies the malware as “PoisonedRefresh.” The second-stage implant intercepts Apache PHP file-loading operations and injects a PHP web shell into the in-memory copies of legitimate BIG-IP APM webtop scripts.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The injected webshell accepts specially formatted requests, decrypts their contents, [and] executes them through PHP's eval() function. | The local communication socket ... can launch an interactive Bash shell without opening a TCP listening port.
The second-stage sample hides key operational strings with RC4.
The implant creates a modified in-memory view containing both the embedded web shell and the original script content. The on-disk file does not need to contain the final web shell content at all.
The sample explicitly targets __libc_start_main and replaces it with a wrapper function... wrapper() runs implant initialization [and] then calls the real main.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A second-stage Linux rootkit targeting F5 BIG-IP APM systems. It hooks __libc_start_main and Apache's APR module loader to execute before normal application startup, intercept PHP file operations, and inject a fileless PHP web shell into memory while leaving on-disk PHP files unchanged. The web shell processes specially formatted requests, decrypts and evaluates supplied PHP code, and disguises output as HTTP 201 CSS responses. It also creates a password-protected local UNIX-socket backdoor capable of launching an interactive Bash shell.
A staged Linux implant targeting BIG-IP APM webtop environments running Apache and PHP. Its infected httpd second stage executes before main(), hooks APR and libphp APIs, alters mapped PHP scripts in memory to prepend an encrypted PHP web shell, and creates an authenticated AF_UNIX socket at /run/bigtlog.pipe that can launch /bin/bash. The related umount installer component infects /usr/sbin/httpd, persists through BIG-IP upgrades, and modifies SELinux configuration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.