Security
F5 BIG-IP Devices Hit by Stealthy Linux Rootkit
Sophos uncovers a second-stage rootkit on F5 BIG-IP APM systems, injecting web shells into memory and evading detection.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Hackers Deploy Linux Rootkit on F5 BIG-IP APM Devices
Sophos researchers have analyzed a Linux rootkit targeting F5 BIG-IP APM environments that intercepts PHP file loading and injects a fileless web shell directly into memory, avoiding writing malicious code to disk. The malware shows signs of being a second-stage payload likely deployed after exploitation of CVE-2025-53521, a critical remote code execution flaw that F5 Networks reclassified from a denial-of-service problem in March. Sophos learned the same malware was analyzed by ESET, which identifies it as PoisonedRefresh.
The malicious installer infected the Apache /usr/sbin/httpd executable used on BIG-IP APM systems, modified SELinux configurations, and achieved persistence across BIG-IP upgrade images. The rootkit starts with Apache, intercepting PHP file operations and modifying them in memory to hide a web shell in legitimate scripts, including apm_css.php3, full_wt.php3, and webtop_popup_css.php3. The PHP files on disk remain unchanged, significantly reducing the detection surface. The injected webshell accepts specially formatted magic requests, decrypts their contents, executes them through PHP’s eval() function, and returns an HTTP 201 response disguised as CSS content. The ShadowServer Foundation reports that 795 endpoints were exposed online yesterday.
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit →
Chinese Hackers Use AI Agents on Stolen Networks to Speed Up Attacks
Chinese hacker groups are using artificial intelligence agents on compromised networks to automate cyberattacks and avoid detection, according to Google’s Threat Intelligence Group report. The report describes a shift by state-backed intelligence agencies and cybercrime gangs from basic AI prompts to advanced AI agents capable of running entire hacking campaigns with little human intervention. Google’s findings indicate these AI-powered attacks reduce the time needed for cyber operations, with some campaigns taking less than six hours from start to finish.
Researchers at Palo Alto Networks Unit 42 found that Chinese-speaking threat actors have begun deploying AI agent frameworks that autonomously perform reconnaissance and attempt to exploit multiple vulnerabilities. U.S. critical infrastructure operators are seeing signs of AI-assisted hacking, including faster exploitation of newly discovered software flaws and the use of automated phishing tools. The bulletin warns that over the next six to nine months, attackers will increasingly experiment with autonomous AI agents, making rapid vulnerability remediation and strong authentication more essential. Cybersecurity expert Kevin Mandia said AI will democratize hacking, enabling sophisticated attacks by smaller criminal groups and less-skilled actors.
Chinese Hackers Use AI On Stolen Networks To Speed Up Attacks →
North Korea Trojanized HAProxy in South Korea, Turning SSL Termination Into Wiretap
Rapid7 documented a previously unknown Linux framework, named ted after debug strings in the binary, that embedded itself into HAProxy load balancer binaries at two South Korean organizations and operated undetected for an estimated nine to ten months. The toolkit did not exploit a vulnerability in HAProxy but replaced the legitimate binary entirely. The attack exploited the load balancer’s role as the SSL/TLS termination point, where HTTPS connections are decrypted before forwarding to backend servers, allowing attackers to read, alter, and log decrypted web sessions without touching backend servers or leaving entries in HAProxy’s own logs.
Rapid7 attributed the campaign with medium confidence to DPRK-aligned threat actors, noting overlaps with APT37 and the Lazarus Group. The victims were in South Korea’s automotive and media sectors. The implant directly modified HAProxy’s internal connection counters, so connections never appeared in statistics or logs. Once inside the edge server, the actor deployed an SSH keylogger and a stager that deployed curlRAT, a libcurl-based remote access trojan. Upgrading HAProxy does not remove the backdoor, as the binary on disk may remain trojanized unless the upgrade is performed cleanly. Rapid7 advises verifying binary integrity against official SHA-256 release hashes.
North Korea Trojanized HAProxy in South Korea, Turning SSL Termination Into Wiretap →
UAE Calls for Cyber Geneva Convention to Treat Major Cyberattacks as Acts of War
The UAE has called for a new international Cyber Geneva Convention to establish rules for cyberwarfare and recognize major attacks on critical digital infrastructure as acts of war. Dr Mohamed Al Kuwaiti, Head of the UAE Cyber Security Council, said several initiatives at the United Nations have sought to establish such a framework, but no convention currently exists. He spoke on the second day of the Hili Forum during a session titled Data, Drones, Digital (Dis) Order in Abu Dhabi on Tuesday, September 8, where experts discussed how AI, cyberwarfare and autonomous systems are changing modern conflict.
The discussion followed remarks by Dr Anwar Gargash that Iran launched 3,300 missiles and drones at the UAE during the recent conflict, with most targeting civilian infrastructure and the majority intercepted by the country’s air defences. Daniel Mouton of Lockheed Martin said the 3,300 threats were an extraordinary volume compressed into a six-week period, making it impossible for any single defence system or operator to manage them alone. Talal AlKaissi of Core42 said strategic autonomy increasingly had to be understood in technological terms, with AI becoming a decision-making layer across financial services, healthcare, logistics, government, and the military. Al Kuwaiti said the UAE’s approach was based on partnerships, including public-private and international cooperation.
UAE calls for ‘Cyber Geneva Convention’ to treat major cyberattacks as acts of war →