Skip to main content

Threats Tagged 'rootkit'

View all threats tagged with 'rootkit'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: rootkit

Threats Tagged 'rootkit'

Click on any threat for detailed analysis and mitigation recommendations

A report surfaced on Reddit about a rootkit named '844ljfpvz.sys' that is signed with a WHQL Microsoft certificate. The information is limited and primarily sourced from a social media link without detailed technical analysis or vendor confirmation. No affected software versions or exploitation details are provided. The rootkit's Microsoft WHQL signature suggests it may bypass some security controls, but no official advisory or patch information is available.

Join the discussion

Elastic Security Labs analyzes VoidLink, a sophisticated Linux malware framework combining Loadable Kernel Modules (LKMs) and eBPF for persistence. The rootkit, developed by a Chinese-speaking threat actor, evolved through four generations, targeting kernels from CentOS 7 to Ubuntu 22.04. VoidLink employs advanced techniques like delayed initialization, runtime key rotation, and a hybrid LKM-eBPF architecture for comprehensive stealth. Notable features include an ICMP-based covert channel, process protection, and memfd-aware boot loading. Evidence suggests AI-assisted development, lowering the barrier for kernel-level rootkit creation. Detection strategies and defensive recommendations are provided to counter this emerging threat.

Join the discussion

The Sysdig Threat Research Team analyzed VoidLink, a sophisticated Linux malware framework targeting cloud environments. Key findings include the first documented Serverside Rootkit Compilation, Chinese development with AI assistance, adaptive detection evasion, and use of the Zig programming language. VoidLink employs a multi-stage loader architecture, fileless execution techniques, and kernel-level stealth mechanisms. It features three control channels, including a covert ICMP channel, and specialized functionality for cloud and container environments. Despite its sophistication, VoidLink can be detected using runtime monitoring tools. The malware shows indicators of Chinese-speaking developers with significant kernel expertise, likely using AI-assisted development methods.

Join the discussion
0

VoidLink is an advanced malware framework designed for Linux systems, focusing on cloud and container environments. It includes custom loaders, implants, rootkits, and modular plugins for long-term access. The framework employs a flexible architecture with a Plugin API inspired by Cobalt Strike. VoidLink uses multiple security mechanisms, including runtime code encryption and adaptive behavior based on the detected environment. Developed by Chinese-affiliated developers, it demonstrates high technical expertise across multiple programming languages. The framework includes cloud-focused capabilities, credential harvesting, and various command-and-control channels. While its intended use remains unclear, VoidLink appears to be positioned for potential commercial use.

Join the discussion

Mustang Panda, a known threat actor, has deployed a signed kernel-mode rootkit to stealthily load the TONESHELL backdoor on targeted systems. This advanced malware leverages a legitimate digital signature to evade detection and gain deep system privileges, enabling persistent and covert access. The rootkit operates at the kernel level, allowing it to manipulate core OS functions and hide its presence effectively. Although no known exploits are currently observed in the wild, the sophistication and stealth capabilities of this threat pose a significant risk. European organizations, especially those in critical infrastructure and government sectors, could face severe confidentiality and integrity breaches if targeted. Mitigation requires advanced endpoint detection, strict driver signature enforcement, and continuous monitoring for anomalous kernel activity. Countries with high adoption of Windows systems and strategic geopolitical relevance are most likely to be affected. Given the high potential impact and complexity of exploitation, this threat is assessed as high severity. Defenders must prioritize detection of signed kernel drivers and implement layered security controls to prevent unauthorized kernel-level code execution.

Join the discussion

In mid-2025, a malicious driver file was discovered on Asian computer systems, signed with a compromised digital certificate. This driver injects a backdoor Trojan and protects malicious files, processes, and registry keys. The final payload is a new variant of the ToneShell backdoor, associated with the HoneyMyte APT group. The attacks, which began in February 2025, primarily target government organizations in Southeast and East Asia, especially Myanmar and Thailand. The malware uses various techniques to evade detection, including API obfuscation, process protection, and registry key protection. The ToneShell backdoor communicates with command-and-control servers using fake TLS headers and supports remote operations such as file transfer and shell access.

Join the discussion

The 'HijackServer' malicious IIS module is actively compromising IIS servers by exploiting exposed ASP . NET machine keys, enabling unauthenticated remote command execution. This threat, attributed to the RudePanda group, uses a customized rootkit and off-the-shelf tools to maintain persistent access. While primarily used to manipulate search engine results for cryptocurrency scams, the module's capabilities allow attackers or third parties to conduct espionage or build malicious infrastructure. Hundreds of servers worldwide have been affected, indicating a broad impact. The exploitation does not require authentication, and the attack leverages a critical misconfiguration or exposure of sensitive cryptographic keys. European organizations running IIS with exposed ASP . NET machine keys are at risk, especially those in countries with high IIS usage and strategic value. Mitigation requires immediate review and protection of ASP . NET machine keys, deployment of advanced monitoring for rootkit activity, and hardening of IIS configurations.

Join the discussion

A high-severity vulnerability in Cisco switches' SNMP implementation has been exploited by hackers to deploy a rootkit, enabling persistent unauthorized control over network switches. Although no specific affected versions or patches have been disclosed, the exploitation allows attackers to compromise the integrity and availability of critical network infrastructure. This threat poses significant risks to European organizations relying on Cisco networking equipment, potentially disrupting operations and enabling further lateral attacks. Mitigation requires immediate network monitoring for anomalous SNMP activity, restricting SNMP access to trusted hosts, and applying any forthcoming Cisco security updates promptly. Countries with high Cisco market penetration and critical infrastructure reliance, such as Germany, France, and the UK, are most at risk. Given the rootkit deployment and ease of exploitation without user interaction, the threat severity is assessed as high. Defenders must prioritize detection and containment to prevent persistent compromise of network devices.

Join the discussion

LinkPro is a newly discovered Linux rootkit that leverages eBPF (extended Berkeley Packet Filter) technology to stealthily hide its presence on infected systems. It activates upon receiving specially crafted 'magic' TCP packets, allowing attackers to control compromised hosts covertly. This rootkit's use of eBPF, a legitimate kernel feature, makes detection challenging as it operates at a low level within the Linux kernel. Although no known exploits are currently reported in the wild, the rootkit's capabilities pose a significant risk to Linux-based infrastructure. European organizations relying on Linux servers, especially those exposed to external networks, could be targeted. The rootkit threatens system confidentiality, integrity, and availability by enabling persistent unauthorized access and potential data exfiltration or sabotage. Mitigation requires advanced monitoring of eBPF programs, network traffic analysis for anomalous TCP packets, and strict kernel security policies. Countries with high Linux adoption in critical sectors and strategic geopolitical relevance are more likely to be affected. Given its stealth, activation method, and potential impact, this threat is assessed as high severity. Defenders should prioritize detection and containment strategies tailored to eBPF misuse and network-based triggers.

Join the discussion

Singularity is a modern stealth Linux kernel rootkit recently analyzed in a detailed blog post by Kyntra. It represents an advanced persistent threat capable of deeply compromising Linux systems by operating at the kernel level, enabling attackers to hide processes, files, and network activity. Although no known exploits in the wild have been reported yet, the rootkit's stealth capabilities and kernel-level access pose significant risks to system confidentiality and integrity. European organizations relying on Linux servers, especially in critical infrastructure and technology sectors, could face targeted attacks leveraging such rootkits. Mitigation requires advanced kernel integrity monitoring, strict access controls, and proactive threat hunting focused on kernel anomalies. Countries with high Linux adoption in enterprise and government environments, such as Germany, France, and the Netherlands, are more likely to be affected. Given the rootkit's complexity, stealth, and potential for deep system compromise without user interaction, the threat severity is assessed as high. Defenders should prioritize detection capabilities for kernel-level threats and ensure rapid incident response readiness.

Join the discussion

Showing 1 to 10 of 16 results

Filters:Tag: rootkit
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses