LinkPro Linux Rootkit Uses eBPF to Hide, Activates via Magic TCP Packets
An investigation into a compromise of Amazon Web Services, AWS, hosted infrastructure uncovered a new GNU/Linux rootkit named LinkPro, according to Synacktiv. The backdoor relies on two eBPF, extended Berkeley Packet Filter, modules for stealth and remote activation. The initial access vector was an exposed Jenkins server exploited via CVE-2024-23897, after which a malicious Docker […]
LinkPro Linux Rootkit Uses eBPF to Hide, Activates via Magic TCP Packets Read More »









