logo

New Snapekit Rootkit Malware Targeting Arch Linux Users

ID: 130f0005-d38f-572f-9fe7-736d28d78752

STIX ID: report--130f0005-d38f-572f-9fe7-736d28d78752

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2024-10-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Snapekit is a newly reported, sophisticated rootkit targeting Arch Linux (kernel 6.10.2-arch1-1 on x86_64). The malware hooks 21 system calls and uses a user-space dropper with multiple anti-analysis protections — including sandbox, debugger and disassembler detection, ptrace checks, and code obfuscation — to evade detection and analysis; the author ('Humzak711') has indicated plans to open-source the project, which could broaden its impact. The report provides technical behavior and mitigation recommendations for researchers but does not include IOCs or evidence of active in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.