All CosmicBytez Labs articles tagged #Rootkit, across news, security advisories, how-to guides, and projects.
A stealthy Linux rootkit dubbed PoisonedRefresh hooks PHP on F5 BIG-IP APM webtop servers to run in-memory web shells that leave disk files untouched.
Sophos found a stealthy Linux rootkit hooking PHP on F5 BIG-IP APM servers to inject memory-only web shells, leaving disk files untouched.
UAT-10147 uses agentic AI to automate attacks on 170,000 web servers, deploying SPECTRE with BYOVD EDR bypass and an AI-assisted Linux kernel rootkit.
Lazarus Group weaponized a Windows afd.sys kernel flaw to reach SYSTEM, deploy the FudModule rootkit killing 94 EDR channels, and drop new backdoors.
This week's threat intelligence bulletin covers Linux rootkit campaigns, an actively exploited router zero-day, AI-assisted intrusions, new scam kit...