www.synacktiv.com/en/publicati...
www.synacktiv.com/en/publicati...
Our #CSIRT team discovered and named LinkPro, a new Linux rootkit, during an incident response. It exploits eBPF for evasion and persistence.
Here are the four key technical points in the image below. 💡
🔗 www.synacktiv.com/en/publicati...
Our #CSIRT team discovered and named LinkPro, a new Linux rootkit, during an incident response. It exploits eBPF for evasion and persistence.
Here are the four key technical points in the image below. 💡
🔗 www.synacktiv.com/en/publicati...
https://securitylabs.datadoghq.com/articles/detection-primitives-for-ebpf-rootkits/
#blueteam, #linux, #threatintel, #ebpf
https://securitylabs.datadoghq.com/articles/detection-primitives-for-ebpf-rootkits/
#blueteam, #linux, #threatintel, #ebpf
Introduction: The New Generation of Invisible Linux Malware Linux has long been considered one of the most secure and stable operating systems in the world, powering everything…
Introduction: The New Generation of Invisible Linux Malware Linux has long been considered one of the most secure and stable operating systems in the world, powering everything…
Théo Letailleur published an article with a detailed description of an eBPF rootkit that hides itself on the compromised system and activates its features upon receiving a "magic packet".
www.synacktiv.com/en/publicati...
Théo Letailleur published an article with a detailed description of an eBPF rootkit that hides itself on the compromised system and activates its features upon receiving a "magic packet".
www.synacktiv.com/en/publicati...