Skip to content
Threat Feed

Tag

Rootkit

6 briefs RSS
high advisory

Detect Linux Kernel Module Load via Built-in Utility

This threat involves adversaries with root privileges using the `insmod` or `modprobe` utilities to load malicious Linux kernel object files (.ko), often rootkits, which provides complete system control and evasion capabilities, making detection of this uncommon activity critical.

linux persistence defense-evasion rootkit endpoint-security threat-detection elastic-defend
1r 2t
medium advisory

Detecting Malicious Kernel Module Loading via Built-in Utilities on Linux

Threat actors with root privileges can leverage built-in Linux utilities like `insmod` or `modprobe` to load kernel object files, often for installing rootkits that grant complete system control and enable evasion of security products, representing a significant persistence and defense evasion technique.

persistence defense-evasion rootkit linux endpoint
1r 1t
critical advisory

Atomic Arch Campaign Leverages Orphaned AUR Packages for Linux Payload Deployment

The Atomic Arch campaign compromises orphaned Arch User Repository (AUR) packages, modifying their PKGBUILDs to install malicious npm/Bun dependencies like 'atomic-lockfile,' which deploy a Linux payload with credential harvesting, eBPF-based stealth, anti-debugging, and data exfiltration capabilities, impacting approximately 1,500 packages.

Arch User Repository +2 supply-chain-attack npm bun linux malware credential-harvesting eBPF rootkit +1
3r 14t 6i
high advisory

Suspicious Kernel Module Load from Unusual Location (Linux)

This alert detects the loading of Linux kernel modules from non-standard directories, potentially indicating malicious persistence or rootkit activity.

Kernel kernel-module persistence rootkit linux
2r
high advisory

Linux Kernel Module Load from Unusual Location

This rule detects the loading of a kernel module from an unusual location, which could indicate a rootkit attempting to maintain persistence on the system by hiding processes, files, or network activity.

Linux Kernel persistence defense-evasion rootkit linux
3r 2t
high advisory

Katana Mirai Variant Targeting Android TV Devices

Katana is a Mirai botnet variant that infects Android TV set-top boxes and compiles its own rootkit for persistence and control.

Android TV mirai botnet android rootkit
2r 7t