National Cyber Warfare Foundation (NCWF)

LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets


0 user ratings
2025-10-16 15:23:58
milo
Blue Team (CND) , Red Team (CNA) , Attacks
An investigation into the compromise of an Amazon Web Services (AWS)-hosted infrastructure has led to the discovery of a new GNU/Linux rootkit dubbed LinkPro, according to findings from Synacktiv.
"This backdoor features functionalities relying on the installation of two eBPF [extended Berkeley Packet Filter] modules, on the one hand to conceal itself, and on the other hand to be remotely



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/10/linkpro-linux-rootkit-uses-ebpf-to-hide.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Red Team (CNA)
Attacks



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.