F5 BIG-IP APM Grew a Fileless Rootkit. Hashes Will Not Save You
Sophos and ESET describe PoisonedRefresh: a Linux implant that serves a PHP web shell from memory on BIG-IP APM webtop files. Disk looks clean. Check mmap, a pipe, and HTTP 201 pretending to be CSS.