Found this article in securelist
https://www.securelist.com/en/blog/208193935/New_64_bit_Linux_Rootkit_Doing_iFrame_Injections
There is also a detailed analysis of the rootkit here
http://blog.crowdstrike.com/2012/11/http-iframe-injecting-linux-rootkit.html