#LinuxRootkit
Red Heron nutzt kritische Gitea-Lücke für internationale Cyberangriffe

#Cyberangriff @acronis #Cybersecurity #Cybersicherheit #Gitea #Linux #LinuxRootkit #RedHeron #Schadsoftware

netzpalaver.de/2026/09/14/r...
September 24, 2026 at 1:36 PM
Red Heron nutzt kritische Gitea-Lücke für internationale Cyberangriffe

Acronis_de #Cybersecurity #Cybersicherheit #Gitea #Linux #LinuxRootkit #RedHeron #Schadsoftware Acronis

netzpalaver.de/2026/...
September 14, 2026 at 1:50 PM
F5 BIG-IP APM Malware Installs a PHP Web Shell Into Memory, Escaping Disk Scans #F5BIGIPAPM #Linux #LinuxRootKit
F5 BIG-IP APM Malware Installs a PHP Web Shell Into Memory, Escaping Disk Scans
Sophos X-Ops has found an advanced Linux rootkit that can conceal a PHP web shell completely in server memory, which makes it harder for traditional security tools to detect.  The malware was analyzed in infected environments consisting of F5 BIG-IP Access Policy Manager (APM) and was discovered by Sophos as Linux/Agnt-IC. “The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows, suggesting it was developed for specific environments,” Sophos reported. About the research The research was posted on September 7, 2026, and shows how the rootkit interferes with the PHP runtime and Apache web server to deploy malicious code without making major modifications to authentic PHP files stored on the device. A Web Shell That Does Not Remain on Disk One significant feature of the malware is that it can install malicious PHP code directly into the running web server’s memory. Generally, threat actors planting a PHP web shell would also modify or make a PHP file on the server. Security teams can then detect the malicious file via antivirus scans, manual investigation, or file-integrity monitoring. The rootkit detailed by Sophos takes another approach. It changes how PHP files are shown to the running Apache process while the original files on disk are left unchanged. This means that a file scan could demonstrate that a PHP is authentic even when the server is actively running malicious code. Rootkit Hooks PHP and Apache Researchers at Sophos discovered that the implant deploys various sophisticated approaches to take command over the web server. It integrates into the device’s startup process and surveys Apache activity to find out when the PHP module is loaded.  After this, the malware can bring its own web-shell functionality and change the in-memory PHP environment.  The installed web shell gets specially tailored HTTP requests and runs commands given by the threat actor. Sophos also found the implant deploying a Unix domain to socket to offer another path of communicating with an infected system and launching a shell.  This combination allows attackers several ways of maintaining access while covering the traces left on the filesystem. Hard to detect The attack has become a problem for experts as the malware does not always have to alter files to attack a server. Security teams should check beyond traditional file-integrity check and analyze memory activity, network traffic and running processes. Sophos recommends that security teams look beyond conventional file-integrity checks and examine network traffic, running processes and memory activity.
dlvr.it
September 10, 2026 at 12:46 PM
UAT-10147 Uses AI to Scale Server Attacks Deploys SPECTRE With EDR Bypass and Linux Rootkit reconbee.com/uat-10147-us...

#UAT10147 #scaleserverattacks #SPECTRE #EDRBypass #linuxrootkit
UAT-10147 Uses AI to Scale Server Attacks Deploys SPECTRE With EDR Bypass and Linux Rootkit
employing AI to improve attacks read more about UAT-10147 Uses AI to Scale Server Attacks Deploys SPECTRE With EDR Bypass and Linux Rootkit
reconbee.com
August 24, 2026 at 12:15 PM
Zero-days, cloud abuse, rootkits, and AI-driven intrusions define this week’s threat roundup, with Pwn2Own Berlin 2026 revealing 47 flaws and attackers hiding inside trusted tools and normal workflows. #Pwn2Own #CloudAbuse #LinuxRootkit
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories
This week’s cybersecurity roundup shows attackers increasingly abusing trusted tools, cloud features, and legitimate services instead of forcing obvious break-ins. From Pwn2Own Berlin 2026 zero-days and Composer token leakage to Storm-2949 cloud abuse, Gunra ransomware, OrBit rootkit activity, and AI-driven intrusions, the pattern is faster, stealthier, and built around normal workflows....
www.hendryadrian.com
May 21, 2026 at 11:00 PM
VoidLink is a sophisticated hybrid Linux rootkit using AI-assisted development, combining LKM and eBPF for covert ICMP C2, anti-debugging, module cloaking, and memfd persistence. Tied to Alibaba Cloud. #LinuxRootkit #AlibabaCloud #China
Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
The leaked source code reveals VoidLink as a multigenerational, hybrid LKM–eBPF Linux rootkit developed with AI-assisted workflows that provides ICMP-based covert C2, delayed initialization, anti-debugging, module masquerading, and memfd-aware boot persistence. The analysis documents eBPF Netlink-buffer "swallowing" to hide ss entries, multiple kernel-targeted hooking strategies across CentOS 7 to kernel 5/6, and operational artifacts tied to Alibaba Cloud infrastructure. #VoidLink #AlibabaCloud
www.hendryadrian.com
March 25, 2026 at 11:20 PM
Introducing Singularity: A sophisticated Linux rootkit that evades Elastic EDR detection through advanced obfuscation and in-memory execution. Stay informed on evolving cybersecurity threats. #CyberSecurity #LinuxRootkit #EDREvasion Link: thedailytechfeed.com/new-singular...
November 1, 2025 at 4:38 PM
Chinese Houken hackers exploit Ivanti CSA zero-days to deploy advanced Linux rootkits, compromising critical infrastructure. #CyberSecurity #Houken #Ivanti #ZeroDay #LinuxRootkit Link: thedailytechfeed.com/chinese-houk...
July 2, 2025 at 4:34 PM