Tag
UAT-10147 Deploys SPECTRE Cross-Platform Backdoor
2 rules 6 TTPs 2 IOCsThe threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.
Detection of Tainted Kernel Module Loading on Linux
1 rule 2 TTPsThe loading of tainted Linux kernel modules may indicate the presence of rootkits or malicious persistence mechanisms used to bypass security controls and intercept system calls.
Mustang Panda Deploys Signed Kernel-Mode Rootkit with CoolClient Backdoor
3 TTPs 4 IOCsThe threat actor HoneyMyte (Mustang Panda) is utilizing a signed kernel-mode rootkit named msagent.sys to provide stealth capabilities for its CoolClient backdoor, facilitating process, file, and network hiding on compromised Windows systems.
HoneyMyte CoolClient Backdoor Updated with Kernel-Mode Rootkit
1 rule 3 TTPsThe HoneyMyte APT group has enhanced its CoolClient backdoor with a custom kernel-mode driver that hides malicious artifacts and activity from security software on Windows systems.
Detect Linux Kernel Module Load via Built-in Utility
1 rule 2 TTPsThis threat involves adversaries with root privileges using the `insmod` or `modprobe` utilities to load malicious Linux kernel object files (.ko), often rootkits, which provides complete system control and evasion capabilities, making detection of this uncommon activity critical.
Detecting Malicious Kernel Module Loading via Built-in Utilities on Linux
1 rule 1 TTPThreat actors with root privileges can leverage built-in Linux utilities like `insmod` or `modprobe` to load kernel object files, often for installing rootkits that grant complete system control and enable evasion of security products, representing a significant persistence and defense evasion technique.
Atomic Arch Campaign Leverages Orphaned AUR Packages for Linux Payload Deployment
3 rules 14 TTPs 6 IOCsThe Atomic Arch campaign compromises orphaned Arch User Repository (AUR) packages, modifying their PKGBUILDs to install malicious npm/Bun dependencies like 'atomic-lockfile,' which deploy a Linux payload with credential harvesting, eBPF-based stealth, anti-debugging, and data exfiltration capabilities, impacting approximately 1,500 packages.
Suspicious Kernel Module Load from Unusual Location (Linux)
2 rulesThis alert detects the loading of Linux kernel modules from non-standard directories, potentially indicating malicious persistence or rootkit activity.
Linux Kernel Module Load from Unusual Location
3 rules 2 TTPsThis rule detects the loading of a kernel module from an unusual location, which could indicate a rootkit attempting to maintain persistence on the system by hiding processes, files, or network activity.
Katana Mirai Variant Targeting Android TV Devices
2 rules 7 TTPsKatana is a Mirai botnet variant that infects Android TV set-top boxes and compiles its own rootkit for persistence and control.