##Rootkit
3+ YEARS of stealth! We uncovered new tactics used by the perfctl malware, including a userland rootkit & an SSH backdoor (a single SPACE in /etc/passwd!). More insights: blog.exatrack.com/Perfctl-usin... #cybersecurity #threat_hunting #linux #infosec #perfctl #rootkit #ssh #exatrack
Perfctl malware exploiting exposed Portainer agent and using new SSH persistenceExaTrack
blog.exatrack.com
December 17, 2024 at 10:02 AM
BlackPill is a stealthy Linux rootkit made in Rust.

github.com/DualHorizon/...

#rootkit #malware #linux #rust #hypervisor
January 3, 2025 at 5:27 PM
"A new Linux backdoor called 'WolfsBane' has been discovered, believed to be a port of Windows malware used by the Chinese 'Gelsemium' hacking group"

https://buff.ly/4g22qst

#Linux #Malware #Rootkit #Cybersecurity #China
Chinese hackers target Linux with new WolfsBane malware
A new Linux backdoor called 'WolfsBane' has been discovered, believed to be a port of Windows malware used by the Chinese 'Gelsemium' hacking group.
buff.ly
November 22, 2024 at 9:00 PM
Dernière ligne droite ! Plus que 2 semaines pour commander ce numéro avec frais de port offerts ou le dénicher en kiosque.

Rendez-vous sans plus tarder sur boutique.ed-diamond.com/nouveautes/1... pour en savoir plus !

#code #rootkit #python #hack #algo #git
December 5, 2025 at 8:39 AM
Comprenez pour mieux vous protéger : créez votre premier #rootkit avec notre dernier numéro de l'année. Rendez-vous en kiosque dans une semaine !

#programmation #cybersécurité #kernel #code
October 24, 2025 at 7:48 AM
major breakthrough:
I just succeeded in making a linux file hiding rootkit LKM with,
the new kernel version, 6.12.74. Which is..Amazing.
github.com/loneicewolf/...

#github #rootkit #progress #breakthrough
GitHub - loneicewolf/Rootkits-6.12.74: A suit of Linux Rootkits for Kernel 6.12.74
A suit of Linux Rootkits for Kernel 6.12.74. Contribute to loneicewolf/Rootkits-6.12.74 development by creating an account on GitHub.
github.com
April 17, 2026 at 1:41 PM
⚠️ VOIDLINK rootkit evolves stealth tactics

VOIDLINK is a stealthy Windows rootkit abusing kernel drivers to hide processes, files and registry keys. It uses persistence, anti-forensics and evasion to maintain long-term access, complicating detection and incident response.

#ransomNews #rootkit
January 20, 2026 at 10:37 AM
🔍💻 Dive into the world of cyber threats with our latest blog: "Understanding Pumakit: The New Stealthy Linux Rootkit." Stay informed and protected! Read more here: https://innovirtuoso.com/cybersecurity/understanding-pumakit-the-new-stealthy-linux-rootkit #Cybersecurity #Linux #Rootkit #InfoSec
Understanding Pumakit: The New Stealthy Linux Rootkit
Pumakit is a newly discovered Linux rootkit that poses a significant threat to cybersecurity. With its advanced stealth techniques.
innovirtuoso.com
August 23, 2025 at 7:22 AM
If you are a SonciWall SM100 user you need to update your firmware ASAP. A rootkup snuck onto devices and this firmware will (at least according to SonicWall) get rid of it for you. #sonicwall #sm100 #rootkit #malware #updates #security #cybersecurity
SonicWall releases SMA100 firmware update to wipe rootkit malware
SonicWall has released a firmware update that can help customers remove rootkit malware deployed in attacks targeting SMA 100 series devices.
www.bleepingcomputer.com
September 29, 2025 at 3:05 PM
🚨🐧 Arch Linux kullanıcıları dikkat! 400'den fazla AUR paketi ele geçirilerek bilgi hırsızı zararlı yazılım ve eBPF tabanlı rootkit dağıtmak için kullanıldı. r.

📖 Detaylar:
linuxhaber.com/400de...

#ArchLinux #AUR #Linux #CyberSecurity #Rootkit #OpenSource #LinuxHaber
June 14, 2026 at 1:32 PM
Krasse Story. Dachte ich wäre IT-bezogen einigermaßen auf dem Stand. Davon hatte ich keine Ahnung.

Nichtsdestotrotz war mir Autoplay immer suspekt und habe es daher grundsätzlich totgelegt.

#Sony #Rootkit
July 25, 2026 at 6:38 PM
#UNC6148 just turned “end‑of‑life” #SonicWall SMA 100s into undead VPNs—Overstep rootkit, stolen OTP seeds, ransomware on deck. Still hugging that EOL hardware?

Read & subscribe 👉 blog.alphahunt.io/overstep-roo... 🔥🔐

#AlphaHunt #CyberSecurity #SonicWall #Rootkit
July 24, 2025 at 1:09 PM
When a nation-state attacker needs a rootkit to take out security software developed by a small, dedicated team, it's a testament to the effectiveness of the team's efforts. Raising the bar with technology made in Twente! #HitmanPro #Lazarus #rootkit
Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day - Avast Threat Labs
The Lazarus Group is back with an upgraded variant of their FudModule rootkit, this time enabled by a zero-day admin-to-kernel vulnerability for CVE-2024-21338. Read this blog for a detailed analysis ...
decoded.avast.io
February 28, 2024 at 2:52 PM
Notre nouveau numéro vous embarque dans la création de votre premier #rootkit !

RDV en kiosque, profitez de la lecture en ligne ou des frais de ports offerts pour le commander => boutique.ed-diamond.com/nouveautes/1....
November 3, 2025 at 10:36 AM
Découvrez ce qu’est un rootkit, comment il fonctionne et surtout comment vous protéger contre cette menace invisible et dangereuse. #Rootkit #hack #prevention #astuces
Rootkits : Comprendre la Menace et Apprendre à s’en Prévenir
ctrlaltplay.fr
June 20, 2025 at 8:01 AM
Господа арчеводы (и арчебейздоводы на Manjaro, CachyOS, EdeavourOS, etc), вам там подвезли добра в AUR:

https://ioctl.fail/preliminary-analysis-of-aur-malware/

TL;DR: в ~400+ пакетов (о которых известно на данный момент) в AUR добавили малварь, которая ворует креды и имеет встроенный руткит […]
Original post on gts.skobk.in
gts.skobk.in
June 14, 2026 at 4:24 PM
November 10, 2025 at 2:29 PM
Hackers exploit #Cisco SNMP flaw to deploy #rootkit on switches 🔥🕵️‍♂️

Threat actors exploited a recently patched remote code execution vulnerability (CVE-2025-20352) in Cisco networking devices to deploy a rootkit and target unprotected #Linux systems!💥🧱 #news

www.bleepingcomputer.com/news/securit...
Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
Threat actors exploited a recently patched remote code execution vulnerability (CVE-2025-20352) in Cisco networking devices to deploy a rootkit and target unprotected Linux systems.
www.bleepingcomputer.com
October 17, 2025 at 10:33 AM
⚠️ CRITICAL: A Cisco zero-day (CVE-2025-20352) is being actively exploited to install Linux rootkits on network switches. The 'ZeroDisco' campaign targets Catalyst devices. Patch immediately! #Cisco #ZeroDay #CVE #Infosec #Rootkit
October 24, 2025 at 1:32 AM