#LinkPro
Ooh baby you know I'm gonna dig in on a eBPF rootkit analysis.
LinkPro: eBPF rootkit analysis
LinkPro: eBPF rootkit analysis
www.synacktiv.com
October 14, 2025 at 3:58 PM
Synacktiv looks at LinkPro, a new Linux eBPF-based rootkit it found deployed on a customer's hacked AWS infrastructure

www.synacktiv.com/en/publicati...
October 14, 2025 at 7:37 PM
Three Linux rootkits use eBPF to blind ss, netstat, bpftool - and kill your debugger before it attaches. https://intel.threadlinqs.com/threat/TL-2026-2624 #ThreatIntel #CVE_2024_23897 #LinkPro #VoidLink
September 23, 2026 at 2:23 AM
LinkPro: new stealthy #Linux rootkit based on eBPF 🔍️

Our #CSIRT team discovered and named LinkPro, a new Linux rootkit, during an incident response. It exploits eBPF for evasion and persistence.
Here are the four key technical points in the image below. 💡

🔗 www.synacktiv.com/en/publicati...
October 14, 2025 at 2:33 PM
Ebpf rootkit analysis - www.synacktiv.com/en/publicati...
LinkPro: eBPF rootkit analysis
LinkPro: eBPF rootkit analysis
www.synacktiv.com
October 17, 2025 at 12:01 PM
LinkPro Rootkit Attacking GNU/Linux Systems Using eBPF Module to Hide Malicious Activities
LinkPro Rootkit Attacking GNU/Linux Systems Using eBPF Module to Hide Malicious Activities
cybersecuritynews.com
October 17, 2025 at 11:04 AM
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
October 17, 2025 at 12:04 PM
Je viens de faire la demande pour générer le lien facilement. Y a possibilité pour Facedebouc, le Mordor et Linkpro mais pas de génération de lien classique à part une copie de l'url
February 15, 2025 at 9:06 AM
Nice bit of work from Datadog, looking at how the eBPF threat model has been turns on its head by malware abusing it:

https://securitylabs.datadoghq.com/articles/detection-primitives-for-ebpf-rootkits/

#blueteam, #linux, #threatintel, #ebpf
Detection primitives for eBPF rootkits | Datadog Security Labs
We analyze how VoidLink, LinkPro, and Atomic Arch abuse eBPF helpers to hide from defenders, and show how to detect them at load time, before they can act.
securitylabs.datadoghq.com
July 27, 2026 at 7:41 PM
eBPF rootkits like VoidLink and LinkPro hide sockets and kill debuggers with rare helpers. Defenders can spot them early by fingerprinting loaded programs for bpf_probe_write_user, bpf_override_return, and bpf_send_signal. #eBPF #Rootkits #Linux
Detection primitives for eBPF rootkits
Linux eBPF rootkits such as VoidLink, LinkPro, and the Atomic Arch campaign use rare helpers to hide sockets, obscure their own programs, and kill ptrace-based debuggers before the kernel finishes processing them. The article shows that defenders should focus on load-time fingerprinting of eBPF programs because helpers like bpf_probe_write_user(), bpf_override_return(), and bpf_send_signal() reveal malicious intent before the rootkit can conceal itself. #VoidLink #LinkPro #AtomicArch #bpf_probe_write_user #bpf_override_return #bpf_send_signal
www.hendryadrian.com
July 28, 2026 at 8:30 AM
Hidden Linux Threats: How eBPF Rootkits Like VoidLink and LinkPro Are Changing the Future of Kernel-Level Attacks + Video

Introduction: The New Generation of Invisible Linux Malware Linux has long been considered one of the most secure and stable operating systems in the world, powering everything…
Hidden Linux Threats: How eBPF Rootkits Like VoidLink and LinkPro Are Changing the Future of Kernel-Level Attacks + Video
Introduction: The New Generation of Invisible Linux Malware Linux has long been considered one of the most secure and stable operating systems in the world, powering everything from cloud infrastructure and enterprise servers to critical internet services. However, attackers continue to evolve, discovering new ways to operate beneath traditional security controls. A new class of threats, known as eBPF rootkits, represents one of the most advanced examples of stealth-focused Linux malware.
undercodenews.com
July 28, 2026 at 9:16 AM
Originally from DataDog: Detection primitives for eBPF rootkits ( :-{ı▓ #cloudsecurity #datadog #cyberresearch
Detection primitives for eBPF rootkits
We analyze how VoidLink, LinkPro, and Atomic Arch abuse eBPF helpers to hide from defenders, and show how to detect them at load time, before they can act.
securitylabs.datadoghq.com
July 28, 2026 at 12:04 AM
I hate #BPF (Berkeley Packet Filter) but it's mostly unrelated cousin #eBPF is pretty cool. And now it has a new use - helping hide a #rootkit. Bad that #AWS infrastructure was hacked but silver lining that we discovered a new use for eBPF?
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
Synacktiv uncovered LinkPro, a Golang rootkit using eBPF hide/knock modules activated by TCP window 54321.
thehackernews.com
October 20, 2025 at 3:28 PM
LinkPro: eBPF rootkit analysis

Théo Letailleur published an article with a detailed description of an eBPF rootkit that hides itself on the compromised system and activates its features upon receiving a "magic packet".

www.synacktiv.com/en/publicati...
LinkPro: eBPF rootkit analysis
LinkPro: eBPF rootkit analysis
www.synacktiv.com
November 21, 2025 at 1:47 AM
LinkPro Rootkit: New eBPF-Backed GNU/Linux Backdoor Found in Compromised AWS Environments LinkPro Rootkit: New eBPF-Backed GNU/Linux Backdoor Found in Compromised AWS Environments Post Views: 31 Jo...

#News

Origin | Interest | Match
October 30, 2025 at 12:10 PM
LinkPro Rootkit: New eBPF-Backed GNU/Linux Backdoor Found in Compromised AWS Environments LinkPro Rootkit: New eBPF-Backed GNU/Linux Backdoor Found in Compromised AWS Environments Post Views: 30 Jo...

#News

Origin | Interest | Match
October 28, 2025 at 1:13 PM