Skip to content
Threat Feed

Tag

Rootkit

10 briefs RSS
high threat

UAT-10147 Deploys SPECTRE Cross-Platform Backdoor

The threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.

Internet Information Services UAT-10147 backdoor cross-platform rootkit byovd e-commerce-fraud cybercrime agentic-ai web-exploitation +1
2r 6t 2i updated
medium advisory

Detection of Tainted Kernel Module Loading on Linux

The loading of tainted Linux kernel modules may indicate the presence of rootkits or malicious persistence mechanisms used to bypass security controls and intercept system calls.

linux persistence rootkit kernel
1r 2t
high threat

Mustang Panda Deploys Signed Kernel-Mode Rootkit with CoolClient Backdoor

The threat actor HoneyMyte (Mustang Panda) is utilizing a signed kernel-mode rootkit named msagent.sys to provide stealth capabilities for its CoolClient backdoor, facilitating process, file, and network hiding on compromised Windows systems.

Windows HoneyMyte rootkit backdoor espionage malware
3t 4i
high threat

HoneyMyte CoolClient Backdoor Updated with Kernel-Mode Rootkit

The HoneyMyte APT group has enhanced its CoolClient backdoor with a custom kernel-mode driver that hides malicious artifacts and activity from security software on Windows systems.

Endpoint Secure HoneyMyte backdoor rootkit apt windows espionage
1r 3t
high advisory

Detect Linux Kernel Module Load via Built-in Utility

This threat involves adversaries with root privileges using the `insmod` or `modprobe` utilities to load malicious Linux kernel object files (.ko), often rootkits, which provides complete system control and evasion capabilities, making detection of this uncommon activity critical.

linux persistence defense-evasion rootkit endpoint-security threat-detection elastic-defend
1r 2t
medium advisory

Detecting Malicious Kernel Module Loading via Built-in Utilities on Linux

Threat actors with root privileges can leverage built-in Linux utilities like `insmod` or `modprobe` to load kernel object files, often for installing rootkits that grant complete system control and enable evasion of security products, representing a significant persistence and defense evasion technique.

persistence defense-evasion rootkit linux endpoint
1r 1t
critical advisory

Atomic Arch Campaign Leverages Orphaned AUR Packages for Linux Payload Deployment

The Atomic Arch campaign compromises orphaned Arch User Repository (AUR) packages, modifying their PKGBUILDs to install malicious npm/Bun dependencies like 'atomic-lockfile,' which deploy a Linux payload with credential harvesting, eBPF-based stealth, anti-debugging, and data exfiltration capabilities, impacting approximately 1,500 packages.

Arch User Repository +2 supply-chain-attack npm bun linux malware credential-harvesting eBPF rootkit +1
3r 14t 6i
high advisory

Suspicious Kernel Module Load from Unusual Location (Linux)

This alert detects the loading of Linux kernel modules from non-standard directories, potentially indicating malicious persistence or rootkit activity.

Kernel kernel-module persistence rootkit linux
2r
high advisory

Linux Kernel Module Load from Unusual Location

This rule detects the loading of a kernel module from an unusual location, which could indicate a rootkit attempting to maintain persistence on the system by hiding processes, files, or network activity.

Linux Kernel persistence defense-evasion rootkit linux
3r 2t
high advisory

Katana Mirai Variant Targeting Android TV Devices

Katana is a Mirai botnet variant that infects Android TV set-top boxes and compiles its own rootkit for persistence and control.

Android TV mirai botnet android rootkit
2r 7t